Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check logs - 'bug week and planning' #3345

Closed
hcaofec opened this issue Aug 22, 2018 · 1 comment
Closed

Check logs - 'bug week and planning' #3345

hcaofec opened this issue Aug 22, 2018 · 1 comment
Assignees

Comments

@hcaofec
Copy link
Contributor

hcaofec commented Aug 22, 2018

Log review needs to be completed for 'bug week and planning' per the Security Event Review Checklist (https://github.com/fecgov/FEC/wiki/Security-Event-Review-Checklist)

@PaulClark2 PaulClark2 added this to the bugs August 2018 milestone Aug 22, 2018
@hcaofec hcaofec changed the title Check logs - 'bug week and planning' ( week 1 ) Check logs - 'bug week and planning' Aug 29, 2018
@hcaofec
Copy link
Contributor Author

hcaofec commented Aug 29, 2018

FEC-CMS: 2
package.json - 1 Medium
[Med] Snyk: Cross-site Scripting (XSS) (due 10/8) fecgov/fec-cms#2262

requirements.txt - 1 Medium
[Med] Open Redirect (due 10/8) fecgov/fec-cms#2263

OPENFEC: 2
requirements.txt - 1 High, 1 Medium
[High] Snyk: Improper Input Validation - #3344
[Med per Jay] Arbitrary Code Execution (due 9/10) - #3280

FEC-EREGS: 0

FEC-PATTERN-LIB: 4
package.json - 2 medium, 2 Low
[MED] ua-parser-js module - Regular Expression Denial of Service (ReDoS) - fecgov/fec-pattern-library#116
[MED] chownr - Time of Check Time of Use (TOCTOU) - fecgov/fec-pattern-library#127
[LOW] Two low risk modues : lodash and braces - fecgov/fec-pattern-library#117

Add/Update User Accounts:
August 27th 2018, 12:49:04.037 | cms | INFO:home.models: User change: User vmohan was added to group Editors
August 27th 2018, 12:49:04.037 | cms | INFO:home.models: User change: User vmohan was added to group Moderators
August 27th 2018, 12:49:04.028 | cms | INFO:home.models: User change: username vmohan by instance vmohan

Deployer Accounts/Service Keys :
9 service keys found on cloud.gov under fec-beta-fec org

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants