CWE-470 Flaw from Veracode Scan

Issue #423 invalid
Former user created an issue

We are getting CWE-470 flaw (https://cwe.mitre.org/data/definitions/470.html) from Veracode scan where we got 'nimbus-jose-jwt-9.9.3.jar' from Azure Java SDK.

https://cwe.mitre.org/data/definitions/470.html

getCommonSuperClass, line 1023 (27 steps) com/nimbusds/jose/shaded/ow2asm/ClassWriter.java

getCommonSuperClass, line 1017 (26 steps) com/nimbusds/jose/shaded/ow2asm/ClassWriter.java

Can you able to look into it ?

Comments (2)

  1. Log in to comment