• Hi @BPoongan127844 (Community Member)​ 

     

    In order to mitigate the CWE 749 risk, we need to review the method in your JsObject class. Ensure that it does not perform any actions that can vulnerable by injecting malicious untrusted input passed to it. So, If your methods receives any input directly or indirectly, make sure to implement validation on such input to prevent potential injection attacks. Make sure you have the necessary permissions and user consent for executing JavaScript in a "WebView".

     

    If you still have questions I would recommend you schedule a consultation call to discuss.

    You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.

    Regards,

    Kashif

    Expand Post
  • MKim147913 (Community Member)

    Did you fix it? How to fix it? I got the same report.

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.