FDA / open.fda.gov

openFDA web site.

Home Page:http://open.fda.gov

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Critical Vulnerabilities in OpenFDA.gov

JNHQ opened this issue · comments

I'm writing on behalf of a Ion Channel, a cybersecurity firm that monitors the software supply chain for U.S. critical infrastructure. In response to information on the escalating prevalence of software dependency attacks, and in an effort to preclude such an attack on a federal civilian agency infrastructure, we are reaching out to the developers of publicly released federal software projects that have critical and high severity vulnerabilities, to make them aware of these findings and to encourage immediate remediation.

In the case of the OpenFDA.gov web site, our analysis has identified four Critical and fifteen High vulnerabilities (screen shot attached). E-mail info@ionchannel.io for detailed findings or to coordinate further. This is not a sales pitch - all findings will be provided as open data.

OpenFDA.gov Screen Shot.pdf