NASA-PDS / portal-tasks

PDS Portal tasks repo used to track update requests for the website. Actual code and website are managed in separate private repo
https://pds.nasa.gov
0 stars 0 forks source link

[SECURITY] JQuery upgrade needed to avoid possible injection #47

Closed jordanpadams closed 1 year ago

jordanpadams commented 1 year ago

Vulnerability

See email for scan results. Need to upgrade JQuery ASAP. This will most likely be in several places.

Software Version

c-suh commented 1 year ago

Fixed what I could find and the SAs tested yesterday. Returned more results which I'm now addressing.

c-suh commented 1 year ago

"Hopefully resolves" is not actually resolved. Letting SAs know to test again.

c-suh commented 1 year ago

Re-scan is successful!

jordanpadams commented 1 year ago

@c-suh status: reopened due to vulnerability still in tool registry

c-suh commented 1 year ago

5 items addressed (main site, pb-search, data-search, dd-search, and tools-registry) and have asked Steve about the webhelp files.

c-suh commented 1 year ago

Steve is in the process of regenerating the WebHelp files.

c-suh commented 1 year ago

The webhelp files have been regenerated and updated, and I've let the appropriate persons know for a re-scan.

jordanpadams commented 1 year ago

closing this as done for time being. will re-open with specific task if still determined to be an issue

tloubrieu-jpl commented 1 year ago

@c-suh did you get a re-scan after this ticket was closed ?If not can you let @gxtchen know how to request it again ?

c-suh commented 1 year ago

@tloubrieu-jpl have just inquired, as I'm not sure if there was a rescan.

c-suh commented 1 year ago

The response:

We have not heard anything, so I think we are OK for now.

tloubrieu-jpl commented 1 year ago

@gxtchen , @jordanpadams told us that you can use that information for the test validation: "we have requested a re-scan to validate the change, since there was no answer it is considered the scan did not raise any vulnerability issue"