GSA / smartpay-website

SmartPay website
https://federalist-ab31a10d-375d-4040-9324-1ae94e8a36b9.sites.pages.cloud.gov/site/gsa/smartpay-website/
3 stars 0 forks source link

Weak Ciphers Enabled #392

Open JennaySDavis opened 8 months ago

JennaySDavis commented 8 months ago

Issue Level: Moderate First Discovered: 1/11/2020 Remediation Date: 4/10/2020

JennaySDavis commented 8 months ago

A ticket was previously created for this issue. https://github.com/GSA/smartpay-website/issues/281.

JennaySDavis commented 7 months ago

The following WebApp Scan finding was from the decommissioned SPCS; this finding is not valid with the new SPCS.

JennaySDavis commented 6 months ago

We are waiting for Tri and the security team to remove this issue from the POAM before closing the ticket.

JennaySDavis commented 2 months ago

Based on cloud.gov documentation; This is guidance from cloud.gov https://cloud.gov/docs/compliance/domain-standards/ making this issue platform-dependent. Dan stated that there are no application changes that can be made on our side, requesting that it be removed. Dan entered a GSA Generic Request requesting this be removed based on it being a platform dependency.

This issue has been resolved and is no longer listed on the June Vulnerability Scan.