VSilva559058 likes this.
  • Veracode Static Analysis reports flaws of CWE 1174 on .NET applications when it can see a string property without Data Annotations. We recommend using Data Annotations to ensure data is validated appropriately. FluentValidation ( https://fluentvalidation.net/ ) is an excellent .NET validation library, but not one that Veracode Static Analysis currently supports for CWE 1174 (or any other flaw as far as I know).

    If you validation other than Data Annotations we recommend documenting this in a mitigation proposal ( https://help.veracode.com/r/improve_mitigation ) and requesting a manual review from your security team.

    Please also consider registering your idea (with examples) with Veracode Community Ideas at https://community.veracode.com/s/ideas .

     

    Thank you,

    Boy Baukema

    Expand Post
  • RRozinov617494 (Community Member)

    FluentValidation is pretty widely used, so it would be worth for the team to explore and add it to the list.

  • PSekar275174 (Community Member)

    The same here. We use FluentValidation for our CQRS types - Queries and Commands as below

     

    ```

    public record GetSummaryQuery(

        Guid UserId,

        string Channel) : IQuery<SummaryResponse>;

    ```

     

    ```

    public class GetSummaryQueryValidator : AbstractValidator<GetSummaryQuery>

    {

        public GetSummaryQueryValidator()

        {

            RuleFor(command => command.UserId).NotEmpty();

            RuleFor(command => command.Channel).NotEmpty().IsEnumName(typeof(Channel));

        }

    }

    ```

     

    This does the validation for us similar to how data annotations work. Can you please look into this issue? Thanks.

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.