CDR Tickets

Issue Number 3801
Summary Remediate CDR Admin Security Vulnerabilities
Created 2014-09-08 14:19:51
Issue Type Task
Submitted By henryec
Assigned To Kline, Bob (NIH/NCI) [C]
Status Closed
Resolved 2014-09-09 09:09:03
Resolution Duplicate
Path /home/bkline/backups/jira/ocecdr/issue.137605
Description

The security folks periodically scan production systems for vulnerabilities. Looks like they scanned CDR Admin recently and found 49 HIGH vulnerabilities and 80 MEDIUM vulnerabilities.

We have 30 days to remediate the High vulnerabilities and 45 days to remediate the Medium vulnerabilities. If I did my math correctly (and I’ll have to verify if it is 30 weekdays vs calendar days), that puts us at 10/7 (for High) and 10/29 (for Medium) due dates.

Comment entered 2014-09-08 14:20:34 by henryec

Attaching copy of the app scan report.

Comment entered 2014-09-08 14:22:56 by henryec

Copying an email update from Bob on Wednesday, August 27, 2014 3:28 PM:

I've gone through the report, and it all boils down to needing to scrub our CGI parameters. I've attached a spreadsheet listing the scripts and high+medium vulnerabilities reported. The number of rows in my sheet is lower than the total they give for HIGH and MEDIUM vulnerabilities, because they have a bunch of repeats of the same vulnerability for the same script.

The bulk of the problems reported (and likely some problems they missed) can be eliminated by a change to a single line of code to clean up the session parameter. I've checked that change into trunk. For one script I'm recommending dropping the script, since it's no longer needed. For the rest we'll handle high and medium vulnerabilities in the same pass, as the solution for all of the problems is the same. For each script we touch during this exercise, we'll look for and fix any similar problems they might not have caught. I expect we'll be able to take care of the work in a couple of days.

Comment entered 2014-09-09 08:53:31 by Kline, Bob (NIH/NCI) [C]

Isn't this a duplicate of OCECDR-3800?

Comment entered 2014-09-09 09:08:14 by henryec

Hi Bob, I didn't realized you had already opened a ticket. (I had searched for a ticket, but didn't use the same key words!). I will close this ticket and mark it as a duplicate.

Attachments
File Name Posted User
cdr detailed report.pdf 2014-09-08 14:20:34
cdr-security-issues-20140827.xlsx 2014-09-08 14:22:56

Elapsed: 0:00:00.001439