Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check logs Sprint 25.1 Week 2 #5821

Closed
3 tasks
cnlucas opened this issue May 8, 2024 · 1 comment
Closed
3 tasks

Check logs Sprint 25.1 Week 2 #5821

cnlucas opened this issue May 8, 2024 · 1 comment
Assignees
Labels
Security: general General security concern or issue
Milestone

Comments

@cnlucas
Copy link
Member

cnlucas commented May 8, 2024

Log review needs to be completed per the Security Event Review Checklist (https://github.com/fecgov/FEC/wiki/Security-Event-Review-Checklist)

Ref: #5820

  • Check booting workers
  • Check memory usage
  • Make new tickets for sprint 25.2 weeks 1 and 2
    (Note: Copy above links in a browser to view the metrics)
@cnlucas cnlucas added the Security: general General security concern or issue label May 8, 2024
@cnlucas cnlucas added this to the 25.1 milestone May 8, 2024
@pkfec
Copy link
Contributor

pkfec commented May 22, 2024

Following vulnerabilities are flagged using snyk cli and not from synk dashboard. More on snyk dashboard discrepancies on slack thread here :

FEC-CMS: 5
package.json: 2
[Snyk Medium dompurify Template Injection] (fecgov/fec-cms#6206)

requirements.txt: 4
[Snyk Medium - django@4.2.10 Regular Expression Denial of Service (ReDoS)] (fecgov/fec-cms#6268)
[Snyk Medium - requests@requests@2.31.0 Always-Incorrect Control Flow Implementation] (fecgov/fec-cms#6285)
[Snyk Medium - jinja2@3.1.3 Cross-site Scripting (XSS)] (fecgov/fec-cms#6250)
[Snyk Medium - setuptools@65.5.0 Regular Expression Denial of Service (ReDoS)] (fecgov/fec-cms#6269)
Screenshot 2024-05-22 at 3 07 48 PM

openFEC: 2
flyway: 0
package.json: 0
requirements.txt: 2
[Snyk Low] - Log Injection in flask-cors@3.0.10
[Snyk Medium] - requests Always-Incorrect Control Flow Implementation](#5845)
Screenshot 2024-05-22 at 3 09 05 PM

FEC-EREGS: This git repo is archived on May 22, 2024 and is this project is deleted from snyk dashboard as well.

FEC-PATTERN-LIBRARY: None
package.json: 0

Search logs:
In Kibana: No "User changes" found in the past week.
Deployer accounts from cloud.gov dashboard: 10

@pkfec pkfec closed this as completed May 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: general General security concern or issue
Projects
Status: ✅ Done
Development

No branches or pull requests

2 participants