USGS-WiM / WIM-Main-Site

Main Website at wim.usgs.gov
1 stars 5 forks source link

Remediate Vulnerability: Development Configuration Files #119

Closed aaronstephenson closed 2 years ago

aaronstephenson commented 2 years ago

Acunetix reports a configuration file included in the website, specifically:

wim.usgs.gov/status/package.json

This is a medium vulnerability and is a priority.

mitchas commented 2 years ago

@aaronstephenson Is the issue just the fact that the package.json file exists?

I deleted it - it wasn't necessary - just wanted to make sure.

aaronstephenson commented 2 years ago

Yes, that's it. Thanks!