Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check logs sprint 6.6 (Dr. Smith) week 2 #3319

Closed
rjayasekera opened this issue Aug 1, 2018 · 1 comment
Closed

Check logs sprint 6.6 (Dr. Smith) week 2 #3319

rjayasekera opened this issue Aug 1, 2018 · 1 comment
Assignees
Milestone

Comments

@rjayasekera
Copy link
Contributor

Log review needs to be completed for Dr. Smith (Sprint 6.6) week 2 per the Security Event Review Checklist

@rjayasekera rjayasekera added this to the Sprint 6.6 milestone Aug 1, 2018
@fecjjeng
Copy link
Contributor

fecjjeng commented Aug 15, 2018

FEC-CMS: 2

package.json - 1 Medium
[Med] Snyk: Cross-site Scripting (XSS) (due 10/8) fecgov/fec-cms#2262

requirements.txt - 1 Medium
[Med] Open Redirect (due 10/8) fecgov/fec-cms#2263

OPENFEC: 1

requirements.txt: 1
[Med per Jay] Arbitrary Code Execution (due 9/10) - #3280

FEC-EREGS: #0

FEC-PATTERN-LIB: 4

package.json
[MED] ua-parser-js module - Regular Expression Denial of Service (ReDoS) - fecgov/fec-pattern-
library#116
[MED] chownr - Time of Check Time of Use (TOCTOU) - fecgov/fec-pattern-library#127
[LOW] Two low risk modues : lodash and braces - fecgov/fec-pattern-library#117

Add/Update User Account : 0
@fec-jli updated her own username on 8/7, confirmed.

Deployer Accounts/Service Keys :
10 service keys found on cloud.gov under fec-beta-fec org, same as last week

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants