question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

[CVE-2021-23017] Upgrade NGINX version

See original GitHub issue

Hi,

The current NGINX version in the Jitsi Web image [stable-5870] is :

nginx version: nginx / 1.14.2
built with OpenSSL 1.1.1d 10 Sep 2019
TLS SNI support enabled

Following the publication of the security alert CVE-2021-23017, could you update the version of NGINX to 1.20.1 or higher?

Thank you

Issue Analytics

  • State:closed
  • Created 2 years ago
  • Comments:6 (6 by maintainers)

github_iconTop GitHub Comments

github_iconTop Results From Across the Web

Updating NGINX for a DNS Resolver Vulnerability (CVE-2021 ...
... resolution (CVE-2021-23017). We consider the vulnerability to be low-severity, but encourage users to upgrade to the latest versions.
Read more >
Vulnerability Details : CVE-2021-23017
CVE-2021-23017 : A security issue in nginx resolver was identified, ... Product Type, Vendor, Product, Version, Update, Edition, Language.
Read more >
Red Hat: CVE-2021-23017: Important: nginx:1.18 security ...
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS...
Read more >
A new nginx package with the fix for the CVE-2021-23017 ...
A new nginx package with the fix for the CVE-2021-23017 within CentOS 6 ELS has been scheduled for gradual rollout.
Read more >
NGINX Plus and Open Source vulnerability CVE-2021 ... - AskF5
Versions using NGINX Open Source: 1.0.0 - 1.11.2, 1.11.3 ... The Upgrading NGINX Plus section of the NGINX Admin Guide; The NGINX Ingress ......
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found