GSA / data.gov

Main repository for the data.gov service
https://data.gov
Other
587 stars 91 forks source link

SNYK Scan Finding: pyopenssl - Resource Exhaustion #4591

Open FuhuXia opened 7 months ago

FuhuXia commented 7 months ago

_Please keep any sensitive details in Google Drive._

Date of report: 2024-01-16 Severity: Moderate Due date: 2024-04-26

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

https://security.snyk.io/vuln/SNYK-PYTHON-PYOPENSSL-6157250

rshewitt commented 3 months ago

there's currently no fix for this issue yet although some work had been done previously. both are accounted for in catalog and inventory via snyk files. exp dates have been updated.