
Blomgren (Community Member) asked a question.
Many findings in Triage Flaws (SQLi for one) point to a WASC website under the Additional Resources section. This is a website that says it was last updated 12 years ago! It uses http (no HTTPS, no security).
Why does Veracode direct its users to an insecure, non-supported website? Isn't that a pretty big risk while also setting a bad example to application teams who are not well-versed in security and likely going there to learn about information security (kind of ironic too)?
Please reconsider if pointing your users to this website is a good idea. While it might have good information, its not well maintained and is a poor example of fundamental security hygiene and maintenance.
.png)
Hi @Blomgren (Community Member), thanks for reaching out and raising this issue. We've flagged this situation internally and created a JIRA ticket for the team responsible for this area. Thank you!