cancel
Showing results for 
Search instead for 
Did you mean: 

Imediate Action - Magento Security Scan XS Vulnerability APPSEC-1802

Re: Imediate Action - Magento Security Scan XS Vulnerability APPSEC-1802

Hi

See here:  https://community.magento.com/t5/Can-Magento-do/Security-Scan-Tool-source-ips/td-p/96524

i.e.  52.87.98.44

Pretty sure that was the same IP was observed in our logs.  It's part of a big range on AWS:

https://search.arin.net/rdap/?query=52.87.98.44

 

Re: Imediate Action - Magento Security Scan XS Vulnerability APPSEC-1802

Hello MazerStricks

We see 52.87.98.44, but cannot say if that is the only IP or indeed if it periodically changes.

Yesterday we updated to 2.3.2, and yet again the Magento Security Scan fails with this result:

XS Vulnerability - Failed.
XSS Patch not detected (APPSEC-1802)

The suggested action is to:

"the Magento 2.0.16/2.1.92.2.5/2.1.142.2.7/2.1.16  Security Update immediately........."  yet the site is running 2.3.2 !!

Re: Imediate Action - Magento Security Scan XS Vulnerability APPSEC-1802

Same here.. We are running 2.3.2 and the security scan is telling us "XSS Patch not detected (APPSEC-1802)"

Re: Imediate Action - Magento Security Scan XS Vulnerability APPSEC-1802

Hi Jorgb

 

Thanks for the update , appreciated !

That's the exact same message we have been getting.

Are you by any chance using HTML/CSS minification ? we were using this.

So we disabled minification, and all scans ran with "No Issues found"  !!!

Re: Imediate Action - Magento Security Scan XS Vulnerability APPSEC-1802

I am on Magento 2.3.4 and all suddenly getting the "Failed.XSS Patch not detected (APPSEC-1716)".

Did you find a way to resolve this?