Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check logs sprint 6.4 (Maj. Don West) week 1 #3266

Closed
rjayasekera opened this issue Jul 6, 2018 · 1 comment
Closed

Check logs sprint 6.4 (Maj. Don West) week 1 #3266

rjayasekera opened this issue Jul 6, 2018 · 1 comment
Assignees
Milestone

Comments

@rjayasekera
Copy link
Contributor

Log review needs to be completed for Maj. Don West (Sprint 6.4) week 1 per the Security Event Review Checklist

@rjayasekera rjayasekera added this to the Sprint 6.4 milestone Jul 6, 2018
@PaulClark2 PaulClark2 changed the title Log monitoring sprint 6.4 (Maj. Don West) week 1 Check logs sprint 6.4 (Maj. Don West) week 1 Jul 12, 2018
@lbeaufort
Copy link
Member

FEC-CMS: 5 total
package.json - 1 High, 1 Medium
Regular Expression Denial of Service (ReDoS) [HIGH] fecgov/fec-cms#2163
Regular Expression Denial of Service (DoS) [MED] fecgov/fec-cms#1953

requirements.txt - 1 High, 2 Medium
Arbitrary Code Execution [HIGH] fecgov/fec-cms#2182
Information Exposure #1 [MED] fecgov/fec-cms#1954
Information Exposure #2 [MED] fecgov/fec-cms#1955

OPENFEC: 1 total
flyway: 1 High, not applicable. I hit "ignore" but documented this for our records. #3279
package.json: 0
requirements.txt: 1 High
Arbitrary Code Execution [HIGH] #3280

FEC-EREGS: 1 total
Arbitrary Code Execution [HIGH] fecgov/fec-eregs#414

None
FEC-PATTERN-LIB: 3 total
Regular Expression Denial of Service (ReDoS) [MED] fecgov/fec-pattern-library#116
Two low risk issues(reported on Snyc) [LOW] fecgov/fec-pattern-library#117

Add/Update User Account

None
Deployer Accounts/Service Keys
10 service keys found on cloud.gov under fec-beta-fec org

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants