CChowdary293928 (Community Member) asked a question.

Although we have implemented thorough data sanitization to address CWE-201, this vulnerability continues to be flagged in our Veracode scans. Could you advise on additional remediation steps

  • SamHouston (Veracode)

    Hi @CChowdary293928 (Community Member)​ - Our team will need more information to be able to provide remediation steps. You can schedule a consultation call with our AppSec Consulting team, using the green schedule a consultation button on the home page of the community.

  • DKurtz548138 (Community Member)

    We met with someone from the team to discuss this more. This is what were were told. @SamHouston (Veracode)​ 

     

    Hello Dan,

     

    It was nice to assist you today with your agenda to discuss your TypeScript CWE-201 flaws. As discussed, please consider entering a mitigation proposal for these flaws to comment that the data handled here is either not sensitive and/or is getting safely transmitted in a way that does not violate security policies at your organization. Consider leveraging the bulk mitigation approach in the Triage Flaws view to update all these flaws at once with a similar mitigation proposal comment -> https://docs.veracode.com/r/Perform_Multiple_Changes_from_the_Triage_Flaws_Page .

     

    If you would like to see the Veracode Product and static scanner support other ways to no longer report and address CWE-201 flaws aside from having to enter and approve a mitigation proposal -- for instance, other customers have raised interest in having the option to indicate trusted sources of input to not view as taint sources for reporting on certain CWEs -- then please consider raising such ideas and product feedback by making use of our Ideas form in our Veracode Community site at https://community.veracode.com/s/ideas . Note you will need to have created an account in the Community to use this form.

     

    Please let me know how else I can be of assistance regarding this agenda.

     

    Best regards,

     

    Andrew// Application Security Consultant, Veracode

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.