ABS110931 (Community Member) asked a question.

Cross-Site Request Forgery (CSRF) (CWE ID 352) flagged against Constructor of ASP .NET Core Web App (UI)

Hi Team,

 

I have come across recommendations and fix for this CSRF flaw for a constructor of a Web API but I couldn't get any references for fix to this flaw for a constructor of a .NET Web App.

 

Please recommend on the fix required, thank you!


  • TBKF (Veracode)

    Veracode static analysis reports [HttpPost] actions of a controller that do not have the [ValidateAntiForgeryToken] annotation on them. You may find more information about Cross-Site Request Forgery protection in .NET applications here: https://docs.microsoft.com/en-us/aspnet/core/security/anti-request-forgery?view=aspnetcore-6.0.

     

    Unfortunately, sometimes the line number information for these actions is not in the debug symbols and so the fallback is to report it on the controller constructor line. Luckily when this happens, the name of the action is able to be captured and this is reported in the "Attack Vector" field in the flaw details that can be found on the Triage Flaws view. An example of this can be seen here, where "write" is the attack vector:

    image of triage flaws page 

     

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.