Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security scan issues #330

Closed
ckarpinski opened this issue Sep 18, 2023 · 2 comments
Closed

Security scan issues #330

ckarpinski opened this issue Sep 18, 2023 · 2 comments
Labels
not end user testable this ticket can be closed after verified by a dev

Comments

@ckarpinski
Copy link
Contributor

ckarpinski commented Sep 18, 2023

The most recent security scan shows that there are a number of new problems. I dont see a way to attach the file here so will put it in slack

PDF https://assaydepot.slack.com/archives/C031E2NF43T/p1695054185432439

@ckarpinski ckarpinski converted this from a draft issue Sep 18, 2023
@DraxIndustries79
Copy link

@aprilrieger aprilrieger moved this from Ready for Development to In Development in atla_digital_library Jan 16, 2024
@aprilrieger
Copy link
Contributor

aprilrieger commented Jan 16, 2024

  • TLS Version 1.0 Protocol Detection (Score: 8.5)
  • TLS Version 1.1 Protocol Detection and Deprecated (Score: 8.5 and 6.1)
  • SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability (BEAST) (Score: 4.3)
  • SSL/TLS Recommended Cipher Suites (Score: 3.9)
  • Git Repository Served by Web Server (Score: 5.0)
  • Web Application Information Disclosure (Score: 5.0): The application discloses path information in error messages.
  • Web Server Transmits Cleartext Credentials (Score: 4.0): Form fields containing passwords are transmitting data in cleartext.
  • Script Src Integrity Check (Score: 3.9): External script resources are not using integrity checks.

@aprilrieger aprilrieger moved this from In Development to Deploy to Production in atla_digital_library Jan 25, 2024
@aprilrieger aprilrieger added the not end user testable this ticket can be closed after verified by a dev label Jan 25, 2024
@aprilrieger aprilrieger moved this from Deploy to Production to Done in atla_digital_library Jan 26, 2024
@jillpe jillpe closed this as completed Jan 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
not end user testable this ticket can be closed after verified by a dev
Projects
Status: Done
Development

No branches or pull requests

4 participants