GSA / data.gov

Main repository for the data.gov service
https://data.gov
Other
547 stars 87 forks source link

synk finding: SNYK-PYTHON-PYOPENSSL-7161590 #4782

Closed FuhuXia closed 1 week ago

FuhuXia commented 3 weeks ago

Date of report: 2024-05-29 Severity: HIGH Due date: 2024-06-29

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

SNYK-PYTHON-PYOPENSSL-7161590 found in catalog.data.gov

FuhuXia commented 3 weeks ago

This is almost the same issue as https://github.com/GSA/data.gov/issues/4781