⚠️ Static Analysis Update: Veracode has improved support for CWE-798 (Use of Hard-coded Credentials) detection

In last month’s release we added better support for CWE 798 detection but there was a bug in our pattern matching which caused a significant number of FPs for some customers. This has been resolved and the improvement should result in significantly fewer CWE-798 (Use of Hard-coded Credentials) FPs.

 


  • tqwamis144955 (Community Member)

    CWE-798 is a common security weakness that can lead to serious security risks if not properly addressed, so reducing false positives in its detection is crucial for developers and organizations using Veracode's tools.

    If you or your organization use Veracode's static analysis tools, these improvements should help streamline the vulnerability assessment process and reduce the noise caused by false positives, allowing you to focus on addressing real security issues in your codebase.

    Expand Post

Topics (8)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.