Issue Number | 3801 |
---|---|
Summary | Remediate CDR Admin Security Vulnerabilities |
Created | 2014-09-08 14:19:51 |
Issue Type | Task |
Submitted By | henryec |
Assigned To | Kline, Bob (NIH/NCI) [C] |
Status | Closed |
Resolved | 2014-09-09 09:09:03 |
Resolution | Duplicate |
Path | /home/bkline/backups/jira/ocecdr/issue.137605 |
The security folks periodically scan production systems for vulnerabilities. Looks like they scanned CDR Admin recently and found 49 HIGH vulnerabilities and 80 MEDIUM vulnerabilities.
We have 30 days to remediate the High vulnerabilities and 45 days to remediate the Medium vulnerabilities. If I did my math correctly (and I’ll have to verify if it is 30 weekdays vs calendar days), that puts us at 10/7 (for High) and 10/29 (for Medium) due dates.
Attaching copy of the app scan report.
Copying an email update from Bob on Wednesday, August 27, 2014 3:28 PM:
I've gone through the report, and it all boils down to needing to scrub our CGI parameters. I've attached a spreadsheet listing the scripts and high+medium vulnerabilities reported. The number of rows in my sheet is lower than the total they give for HIGH and MEDIUM vulnerabilities, because they have a bunch of repeats of the same vulnerability for the same script.
The bulk of the problems reported (and likely some problems they missed) can be eliminated by a change to a single line of code to clean up the session parameter. I've checked that change into trunk. For one script I'm recommending dropping the script, since it's no longer needed. For the rest we'll handle high and medium vulnerabilities in the same pass, as the solution for all of the problems is the same. For each script we touch during this exercise, we'll look for and fix any similar problems they might not have caught. I expect we'll be able to take care of the work in a couple of days.
Isn't this a duplicate of OCECDR-3800?
Hi Bob, I didn't realized you had already opened a ticket. (I had searched for a ticket, but didn't use the same key words!). I will close this ticket and mark it as a duplicate.
File Name | Posted | User |
---|---|---|
cdr detailed report.pdf | 2014-09-08 14:20:34 | |
cdr-security-issues-20140827.xlsx | 2014-09-08 14:22:56 |
Elapsed: 0:00:00.001439