Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Nginx to version 1.20.0 or 1.21.0 due to security issues #3

Open
Alcatraz077 opened this issue Feb 9, 2022 · 0 comments
Open

Comments

@Alcatraz077
Copy link

I believe this is the correct repo for the nginx instance used by lan-cache. I've ran a security scan via Nessus, and came across multiple security vulnerabilities. Updated the underlying server, as well as the containers. Re-ran the scan, and vulnerabilities still exist. As such, I'd like to report them to you and request you update the version of nginx used by lan-cache projects to version 1.20.0 or 1.21.0, as this will close all vulnerabilities listed herein.

The one of most concern is an RCE vulnerability with a CVE score of 9.4. Attached are screenshots from the scan. This scan did take place via the LAN of course, but I'd still rather report these to have it patched if possible.

Attached are screenshots.

nginx-vulns
nginx-9 4CVE
nginx-7 5CVE
nginx-6 1CVE
nginx-5 3CVE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant