
DSudoma170111 (Community Member) asked a question.
I have a lot of CWE 80 issues in my application, but they are seem strange and incorrect.
When I use Veracode Greenlight I do not get the flaw, but we I use scan in CI pipeline I get.
There is the one method as example where I get this CWE 80 flaw
public Service Create(DataSource dataSource)
{
return dataSource switch
{
DataSource.Source1 => serviceProvider.GetRequiredService<Service1>(),
DataSource.Source2 => serviceProvider.GetRequiredService<Service2>(),
_ => throw new NotSupportedException($"Data source {dataSource} is not supported."),
};
}
.png)
Hi @DSudoma170111 (Community Member)
CWE 80 is Basic XSS flaws, these are usually supposed to be reported when your application populates the HTTP response with untrusted input, allowing an attacker to embed malicious content, such as Javascript code, which will be executed in the context of the victim's browser in order to steal cookies and or modify the content presented to the user.
We recommend that any untrusted variables used in the construction of the response be contextually encoded. You can use one of the supported cleansing functions given in this link https://help.veracode.com/r/review_cleansers.
If you are sure that that given code is not trying to produce a part of HTTP response of HTML markup or response that might be rendered as HTTP output. You can accordingly raise False Positive proposal on the same. If you require Veracode to confirm this. I would recommend you schedule a consultation call to discuss. You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.
Regards,
Kashif