ZShaik477640 (Community Member) asked a question.

How should CWE ID 1174 "Improper Model Validation" be handled for API response models in Veracode scans?

 I'm working with thousands of API response models, and Veracode has been repeatedly reporting CWE ID 1174 "Improper Model Validation" against these models. I understand the importance of validating request models to prevent improper data entering the system, but for response models—which are generated by our backend and sent to clients—this seems unnecessary. Is it a real security risk to not validate response models? Are there best practices or configuration changes to suppress or resolve these findings specifically for response models when using Veracode? Any guidance or official recommendations on addressing this would be appreciated.


  • SamHouston (Veracode)

    Hi @ZShaik477640 (Community Member)​ - We have an article about CWE 1174 here that should be helpful: https://community.veracode.com/s/article/NET-Remediation-Guidance-for-CWE-1174

     

    I don't believe the detection makes the distinction between request or response models here but regardless, it is still encouraged to have validation to ensure correctness of all involved models. If you feel that the way your response models are getting generated for your use case is done safely and properly such that having model validation is not a requirement in their eyes, then you can enter a mitigation proposal for the flaws that belong in this evaluation to document this.

     

    On our community homepage, we also have a green "Schedule Consultation" button on the right side of the page. Click that to schedule a call with our AppSec Consultants, they can help you through this

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.