fecgov / openFEC

The first RESTful API for the Federal Election Commission. We're aiming to make campaign finance more accessible for journalists, academics, developers, and other transparency seekers.
https://api.open.fec.gov/developers
Other
479 stars 106 forks source link

Check logs 22.2 Week 2 #5496

Closed pkfec closed 1 year ago

pkfec commented 1 year ago

Log review needs to be completed per the Security Event Review Checklist (https://github.com/fecgov/FEC/wiki/Security-Event-Review-Checklist)

Ref: [Check logs PI 22.2 week 1] (https://github.com/fecgov/openFEC/issues/5495)

cnlucas commented 1 year ago

FEC-CMS: 1 package.json: None requirements.txt: 1 [Snyk High] (Django Regular Expression Denial of Service)[https://github.com/fecgov/fec-cms/issues/5791]

OPENFEC: 1 package.json: None requirements.txt: Flask---On hold with API Key issue

requirements-dev.txt: 1 [Snyk Medium] (Setuptools Regular Expression Denial of Service)[https://github.com/fecgov/openFEC/issues/5477]

FLYWAY: 2 [Snyk High] (Denial of Service)[https://github.com/fecgov/openFEC/issues/5482] [Snyk Low] (Creation of Temporary File in Directory with Insecure Permissions[https://github.com/fecgov/openFEC/issues/5478]

FEC-EREGS: 1 package.json: None requirements.txt: 1 [Snyk High] (Django Regular Expression Denial of Service)[https://github.com/fecgov/fec-eregs/issues/773]

FEC-PATTERN-LIBRARY: package.json: None

Search logs: User change: None

Cloud.gov Dashboard: 6 deployer accounts

Off-boarding: 0

Health check: memory usage: ok booting workers: higher on 6/21 & 7/12 --ok