Blomgren (Community Member) asked a question.

Remediation Guidance points to unsafe legacy website - WASC http://projects.webappsec.org/

Many findings in Triage Flaws (SQLi for one) point to a WASC website under the Additional Resources section. This is a website that says it was last updated 12 years ago! It uses http (no HTTPS, no security).

 

Why does Veracode direct its users to an insecure, non-supported website? Isn't that a pretty big risk while also setting a bad example to application teams who are not well-versed in security and likely going there to learn about information security (kind of ironic too)?

 

Please reconsider if pointing your users to this website is a good idea. While it might have good information, its not well maintained and is a poor example of fundamental security hygiene and maintenance.

 

http://projects.webappsec.org/

http://projects.webappsec.org/w/page/13246927/FrontPage


Blomgren likes this.
  • SamHouston (Veracode)

    Hi @Blomgren (Community Member)​, thanks for reaching out and raising this issue. We've flagged this situation internally and created a JIRA ticket for the team responsible for this area. Thank you!

Topics (7)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.