When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Hi @HSingh424927 (Community Member), Veracode static analysis can report CWE 327 for multiple reasons and so I always recommend checking the flaw details section that contains the detailed description and remediation advice which should point towards the cause more succinctly. This video from our help documentation shows how to find this section: https://www.youtube.com/watch?v=WTF53s02nG8&t=123s.
Besides key length, static analysis could also be reporting use of a hard-coded salt, which should be instead random from a SecureRandom source and >=8 bytes. Static analysis could also be reporting the iteration count which we currently recommend at >=100,000.
You can find a lot of good information about our current cryptography recommendations in these blog posts: https://www.veracode.com/blog/research/encryption-and-decryption-java-cryptography and https://www.veracode.com/blog/research/password-storage-using-java