FDA / openfda

openFDA is an FDA project to provide open APIs, raw data downloads, documentation and examples, and a developer community for an important collection of FDA public datasets.
https://open.fda.gov
Creative Commons Zero v1.0 Universal
569 stars 131 forks source link

Critical and High Vulnerabilities in OpenFDA #129

Closed JNHQ closed 3 years ago

JNHQ commented 4 years ago

I'm writing on behalf of a company that monitors the critical infrastructure software supply chain for U.S. critical infrastructure. In response to information on the escalating prevalence of software dependency attacks, and in an effort to preclude such an attack on a federal civilian agency infrastructure, we are reaching out to the developers of publicly released federal software projects that have critical and high severity vulnerabilities, to make them aware of these findings and to encourage immediate remediation.

Our analysis has identified three Critical and two High vulnerabilities in OpenFDA dependencies. Screen shot is attached. For details on the findings or to coordinate further, e-mail info@ionchannel.io . This is not a sales pitch - all findings will be provided as open data.

OpenFDA Screenshot.pdf