Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check Logs Innovation Week 3 #5469

Closed
3 tasks done
tmpayton opened this issue Jun 7, 2023 · 1 comment
Closed
3 tasks done

Check Logs Innovation Week 3 #5469

tmpayton opened this issue Jun 7, 2023 · 1 comment
Assignees
Labels
Security: general General security concern or issue

Comments

@tmpayton
Copy link
Contributor

tmpayton commented Jun 7, 2023

Log review needs to be completed per the Security Event Review Checklist (https://github.com/fecgov/FEC/wiki/Security-Event-Review-Checklist)

Ref: [Check logs PI Innovation week 2]
(#5468)

(Note: Copy above links in a browser to view the metrics)

@pkfec pkfec added the Security: general General security concern or issue label Jun 13, 2023
@pkfec pkfec added this to the PI 21 innovation milestone Jun 13, 2023
@hcaofec
Copy link
Contributor

hcaofec commented Jun 28, 2023

FEC-CMS: 0
package.json: None
requirements.txt: None

OPENFEC: 3
package.json: None
requirements.txt:
(High) flask Information Exposure #5440
(Medium) requests Information Exposure #5459

requirements-dev.txt:
setuptools Regular Expression Denial of Service (ReDoS) #5477

flyway 2:
(High) Denial of Service (DoS) #5482
(Low) Creation of Temporary File in Directory with Insecure Permissions
#5478

FEC-EREGS: 0
package.json: None
requirements.txt: None

FEC-PATTERN-LIBRARY:
package.json: None

Search logs:
User change: None

Cloud.gov Dashboard: 6 deployer accounts

Off-boarding: 0

Health check:
memory usage: ok
booting workers: ok

@hcaofec hcaofec mentioned this issue Jun 28, 2023
2 tasks
@hcaofec hcaofec closed this as completed Jun 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: general General security concern or issue
Projects
None yet
Development

No branches or pull requests

3 participants