GSA / data.gov

Main repository for the data.gov service
https://data.gov
Other
621 stars 98 forks source link

Invicti finding: bootstrap out-of-data version #4905

Open FuhuXia opened 2 weeks ago

FuhuXia commented 2 weeks ago

_Please keep any sensitive details in Google Drive._

Date of report: 2024-09-13 Severity: Moderate Due date: 2024-12-13

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

FuhuXia commented 2 weeks ago

Upstream issue created on CKAN