VV178539 (Community Member) asked a question.

Below error shows [1] in Veracode flaws when tried to use the spring boot data source username (spring.datasource.username) through properties. Kindly suggest.

[1]
CWE-798 - Use of Hard-coded Credentials: WEB-INF/classes/application.properties

spring.datasource.username uses secrets manager to pull the actual credentials to connect to database. So, The value for this is actually secrets name so it is actually secure but wanted to get some suggestion on how to resolve in Veracode results. Thanks!


Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.