DShah866551 (Community Member) asked a question.

Help required to fix CWE-352 (CSRF) vulnerability in NodeJS/Express code

We have configured Veracode pipeline scan in GitHub Actions pipeline. The pipeline was working fine until last week but suddenly we are noticing failures highlighting CWE-352 (CSRF) issue in NodeJS/Express js code. We haven't modified javascript files in last 1 week and there is no information mentioned on why the Veracode pipeline scan is identifying the issue. Attached screenshot for reference.

 

Please help me with additional details to understand the reason of pipeline failure and potential fix.

 

Is there any update on Veracode side in last 1 week related to this vulnerability in pipeline scanner?


Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.