fecgov / openFEC

The first RESTful API for the Federal Election Commission. We're aiming to make campaign finance more accessible for journalists, academics, developers, and other transparency seekers.
https://api.open.fec.gov/developers
Other
479 stars 106 forks source link

Check logs Sprint 25.1 Week 1 #5820

Closed cnlucas closed 4 months ago

cnlucas commented 4 months ago

Log review needs to be completed per the Security Event Review Checklist (https://github.com/fecgov/FEC/wiki/Security-Event-Review-Checklist)

Ref: https://github.com/fecgov/openFEC/issues/5797

pkfec commented 4 months ago

Following vulnerabilities are flagged using snyk cli and not from synk dashboard. More on snyk dashboard discrepancies on slack thread here :

FEC-CMS: 5 package.json: 2 [Snyk High - es5-ext Regular Expression Denial of Service (ReDoS)] (https://github.com/fecgov/fec-cms/issues/6132) [Snyk Medium dompurify Template Injection] (https://github.com/fecgov/fec-cms/issues/6206)

requirements.txt: 3 [Snyk Medium - django@4.2.10 Regular Expression Denial of Service (ReDoS)] (https://github.com/fecgov/fec-cms/issues/6268) [Snyk Medium - jinja2@3.1.3 Cross-site Scripting (XSS)] (https://github.com/fecgov/fec-cms/issues/6250) [Snyk Medium - setuptools@65.5.0 Regular Expression Denial of Service (ReDoS)] (https://github.com/fecgov/fec-cms/issues/6269)

Screenshot 2024-05-15 at 8 57 15 PM

openFEC: 1 flyway: 0 package.json: 0 requirements.txt: 0 requirements-dev.txt: 1 [Snyk Low] - Log Injection in flask-cors@3.0.10

Screenshot 2024-05-15 at 8 15 56 PM

FEC-EREGS: Pausing the vulnerability checks on this repo. This repo will be deprecated soon!

FEC-PATTERN-LIBRARY: None package.json: 0

Search logs: Kibana logs timed out when searched for "User change" in past 7 days or 30 days Deployer account from cloud.gov dashboard: 10