
VV178539 (Community Member) asked a question.
[1]
CWE-798 - Use of Hard-coded Credentials: WEB-INF/classes/application.properties
spring.datasource.username uses secrets manager to pull the actual credentials to connect to database. So, The value for this is actually secrets name so it is actually secure but wanted to get some suggestion on how to resolve in Veracode results. Thanks!
.png)
Hi VV178539,
If you are using a secret manager and the value is not being used as a hardcoded credentials, you can enter mitigation comments to the flaw and state how the credentials are being managed. See below our documentation to add mitigation comments:
https://docs.veracode.com/r/Propose_Mitigating_Factors_for_a_Flaw
Thanks
Thilagshan