data.gov icon indicating copy to clipboard operation
data.gov copied to clipboard

Netsparker scan 07292022 - update version of bootstrap on strategy.data.gov

Open btylerburton opened this issue 3 years ago • 0 comments

Please keep any sensitive details in Google Drive.

**Date of report: 2022-07-29 Severity: Minor Due date: 2022-10-29

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

  • [X] Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability* (link)

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

Strategy.data.gov is serving an outdated version of the Bootstrap library which may be vulnerable to exploitation

Remediation

Update version of Bootstrap served on strategy.data.gov

btylerburton avatar Aug 11 '22 20:08 btylerburton