Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check logs sprint 9.3 week 2 #3821

Closed
jason-upchurch opened this issue Jun 13, 2019 · 1 comment
Closed

Check logs sprint 9.3 week 2 #3821

jason-upchurch opened this issue Jun 13, 2019 · 1 comment
Assignees
Labels
Security: general General security concern or issue
Milestone

Comments

@jason-upchurch
Copy link
Contributor

jason-upchurch commented Jun 13, 2019

Log review needs to be completed for sprint 9.3 week 2 per the Security Event Review Checklist (https://github.com/fecgov/FEC/wiki/Security-Event-Review-Checklist)

@jason-upchurch jason-upchurch added the Security: general General security concern or issue label Jun 13, 2019
@jason-upchurch jason-upchurch added this to the Sprint 9.3 milestone Jun 13, 2019
@hcaofec
Copy link
Contributor

hcaofec commented Jun 26, 2019

Vulnerabilities found this week
FEC-CMS: Total 3
package.json: 2 HIGH, 1 MEDIUM

Arbitrary File Overwrite (fstream) due 6/15/2019: HIGH fecgov/fec-cms#2901
Arbitrary File Overwrite:(tar) due 5/10/2019 :HIGH fecgov/fec-cms#2821
Denial of Service (DoS)(mem) due 6/2/2019 : MEDIUM fecgov/fec-cms#2792
requirements.txt: 1 LOW
Cross-site Scripting (XSS)(django) : LOW fecgov/fec-cms#2944

OPENFEC: 0
package.json: 0
requirements.txt: 0
data/flyway/build.gradle: 0

FEC-EREGS: Total 1
package.json: 1 MEDIUM

Prototype Pollution (jquery) due 6/10/2019 : MEDIUM fecgov/fec-eregs#439
requirements.txt: 0

FEC-PATTERN-LIBRARY: Total 0
package.json: 0

Users changed this week or last: (Jaime Amrhein was added to Slack)
Search logs: No new users added/removed
Cloud.gov Dashboard: 9 deployer accounts, same as last week.

@hcaofec hcaofec closed this as completed Jun 26, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: general General security concern or issue
Projects
None yet
Development

No branches or pull requests

2 participants