department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
280 stars 195 forks source link

[Nessus Finding] HSTS Missing from HTTPS Server - DUE MAY #80844

Open kell-y opened 3 months ago

kell-y commented 3 months ago

The Feb 2024 Nessus Scan revealed a new medium vulnerability finding on 2/2/24:

HSTS Missing from HTTPS Server, host 10.247.33.45

Nessus Solution: Configure the remote web server to use HSTS

image.png
ph-One commented 3 months ago

Keep in mind that IP addresses mean nothing in our environment. We can dig through CloudTrail and see what instance(s) may have used this IP during this time period, but it's largely a shot in the dark.

gary-fallon commented 2 months ago

https://github.com/department-of-veterans-affairs/va.gov-team-sensitive/issues/440

ph-One commented 2 months ago

Initially I thought this may be from the revproxy, but they are all configured for HSTS. Looking elsewhere.

ph-One commented 2 months ago

Forward Proxy also has HSTS enabled. Looking elsewhere.

kell-y commented 2 weeks ago

Update on 6/24/2024: Infra did a little looking, and a decision was made to wait for the next scan (to be done some time in July) to see if this still appears. Othrwise, Infrastructure has been unable to locate an individual virtual machine based on just an IP address as a data point.

keithdadkins commented 1 week ago

I'm working on setting up a box to perform internal scans and some scripts to help map services to IP addresses. I'll perform a manual scan initially, but intend to build automation we can use if something like this pops up again. I suggest closing this ticket and creating a new one to scan for security headers.

kell-y commented 5 days ago

I think we'll need to keep this ticket to track the finding until it's closed or remediated, but go ahead and open a new one for the work you suggested!