⚠️ Announcement (Action Required): Veracode SAST has recategorized certain CWE-201 flaws to CWE-918 flaws for Python applications

Veracode has determined that our static analysis for Python language submissions was inaccurately reporting certain flaws as CWE-201 flaws (Insertion of Sensitive Information Into Sent Data), when in fact they should have been categorized as CWE-918 (Server-Side Request Forgery (SSRF)) flaws. Recategorization of certain CWE-201 flaws to CWE-918 flaws may impact existing flaw matching and could require new mitigations being applied. We are making these changes in our upcoming April release, please note:

 

  • Any Python application using a policy reliant on the “Auto-Update CWE Top 25” standard with Static flaws of CWE 201 might fall out of compliance.
  • Any Python application using a policy reliant on Severity MEDIUM or higher with Static flaws of CWE 201 might fall out of compliance.
  • Any Python application using a policy reliant on Score with Static flaws of CWE 201 might fall out of compliance.

 

Have any questions or comments? Please leave them below.


Topics (8)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.