Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Issue

A05 Security Misconfiguration – ReadMe File May Identify Site Software

Priority

Status
colourBlue
titleLow

EP Number

Jira Legacy
serverSystem

JIRA

Jira
serverIda2269739-3244-3b4d-bb8f-c582148d7bba
keyEP-3246

Resolution:

We have raised a request with our Hosting Partner - to remove access/delete readme file.

Issue

A05 Security Misconfiguration – Missing Recommended Security Header

Priority

Status
colourBlue
titleLow

EP Number

Jira Legacy
serverSystem

JIRA

Jira
serverIda2269739-3244-3b4d-bb8f-c582148d7bba
keyEP-3247

Resolution

Awaiting further clarification from Pen Testers.

Issue

A05 Security Misconfiguration - Missing Sub resource Integrity (SRI) for External Script

Priority

Status
colourBlue
titleLow

EP Number

Jira Legacy
serverSystem

JIRA

Jira
serverIda2269739-3244-3b4d-bb8f-c582148d7bba
keyEP-3248

Resolution

We have updated external front end dependencies to now have a generated integrity hash, this allows the browser to verify the contents have not been manipulated in transit.

Issue

A05 Security Misconfiguration - Source Map Disclosure

Priority

Status
colourBlue
titleLow

EP Number

Jira Legacy
serverSystem

JIRA

Jira
serverIda2269739-3244-3b4d-bb8f-c582148d7bba
keyEP-3249

Resolution:

We have removed the .map files generated by our front end build process.

Issue

A05 Security Misconfiguration - Swagger API Structure Exposed

Priority

Status
colourBlue
titleLow

EP Number

Jira Legacy
serverSystem

JIRA

Jira
serverIda2269739-3244-3b4d-bb8f-c582148d7bba
keyEP-3250

Resolution:

Adjusted our api_docs endpoint to only be accessible when the application in running in test mode.

Issue

Reopened - Using Components with Known Vulnerabilities - Out-of-Date Components Identified

Priority

Status
colourYellow
titlemedium

EP Number

Jira Legacy
serverSystem

JIRA

Jira
serverIda2269739-3244-3b4d-bb8f-c582148d7bba
keyEP-3253

Resolution:

On the previous Pen Test we had removed all jQuery 2.1.1 from the application, we have now removed the jQuery 2.1.1 files also.

Issue

Reopened - Security Misconfiguration – Potentially Dangerous File Type Upload Allowed

This issue has been partially resolved.

The potentially harmful python file extensions reported in this issue are no longer accepted by the uploader. However, other potentially dangerous file types such as PHP, EXE, and ZIP are still allowed.

Priority

Status
colourYellow
titlemedium

EP Number

Jira Legacy
serverSystem

JIRA

Jira
serverIda2269739-3244-3b4d-bb8f-c582148d7bba
keyEP-3252

Resolution:

Work is scheduled for next sprint.