Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

GSA/data.gov
main @ cb5d8bb
37
Fixes
0
CVEs
CRITICAL
Peak severity
100.0%
Coverage
Highlights
Auth Bypass: 4 prior fixes. Scrutinize any change in this area.
ansible/roles/software/wordpress/datagov-sudo-2-init/templates/datagov.nginx.conf: most-fixed (7 issues). Treat as high-risk during review.
18 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Host Header Injection: Multiple nginx server blocks historically lacked host allowlists, allowing arbitrary Host headers to route to applications.
Auth Bypass: SAML authentication contexts were not requiring PIV/HSPD-12, and a SAML admin endpoint was left accessible, enabling weaker or bypassed authentication.
Secret Exposure: Hardcoded database passwords, SAML secrets, and personal data were exposed in plaintext or overly permissive files, requiring vault rekeying and permission fixes.