Skip to content

Veracode - CWE-117: Improper Output Neutralization for Logs #2127

@vsfeedback

Description

@vsfeedback

I was asked to verify the code I wrote with Veracode. Veracode reports a problem with the Logs "CWE117: Improper Output Neutralization for Logs" but even commenting on all the logs the problem remains. The module indicated by veracode is "microsoft.extensions.logging.abstractions.dll" which is present in the Azure Function v1 SDK.

How can I fix the problem?

Best regards,

Antonino Bambara

This issue has been moved from https://developercommunity.visualstudio.com/content/problem/668379/veracode-cwe-117-improper-output-neutralization-fo.html
VSTS ticketId: 957394

These are the original issue comments:

Visual Studio Feedback System on 7/31/2019, 02:18 AM (31 hours ago):

We have directed your feedback to the appropriate engineering team for further evaluation. The team will review the feedback and notify you about the next steps.



Visual Studio Feedback System on 8/1/2019, 00:32 AM (8 hours ago):

This issue is currently being investigated. Our team will get back to you if either more information is needed, a workaround is available, or the issue is resolved.



These are the original issue solutions:
(no solutions)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions