data.gov
data.gov copied to clipboard
Netsparker scan 07292022 - update version of bootstrap on strategy.data.gov
Please keep any sensitive details in Google Drive.
**Date of report: 2022-07-29 Severity: Minor Due date: 2022-10-29
Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.
- [X] Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability* (link)
* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.
Brief description
Strategy.data.gov is serving an outdated version of the Bootstrap library which may be vulnerable to exploitation
Remediation
Update version of Bootstrap served on strategy.data.gov