
Product Announcements — Mike M (Veracode TPM) (Community Member) asked a question.
Veracode has determined that our static analysis for Python language submissions was inaccurately reporting certain flaws as CWE-201 flaws (Insertion of Sensitive Information Into Sent Data), when in fact they should have been categorized as CWE-918 (Server-Side Request Forgery (SSRF)) flaws. Recategorization of certain CWE-201 flaws to CWE-918 flaws may impact existing flaw matching and could require new mitigations being applied. We are making these changes in our upcoming April release, please note:
- Any Python application using a policy reliant on the “Auto-Update CWE Top 25” standard with Static flaws of CWE 201 might fall out of compliance.
- Any Python application using a policy reliant on Severity MEDIUM or higher with Static flaws of CWE 201 might fall out of compliance.
- Any Python application using a policy reliant on Score with Static flaws of CWE 201 might fall out of compliance.
Have any questions or comments? Please leave them below.
.png)