[CVE-2021-23017] Upgrade NGINX version
See original GitHub issueHi,
The current NGINX version in the Jitsi Web image [stable-5870] is :
nginx version: nginx / 1.14.2
built with OpenSSL 1.1.1d 10 Sep 2019
TLS SNI support enabled
Following the publication of the security alert CVE-2021-23017, could you update the version of NGINX to 1.20.1 or higher?
Thank you
Issue Analytics
- State:
- Created 2 years ago
- Comments:6 (6 by maintainers)
Top Results From Across the Web
Updating NGINX for a DNS Resolver Vulnerability (CVE-2021 ...
... resolution (CVE-2021-23017). We consider the vulnerability to be low-severity, but encourage users to upgrade to the latest versions.
Read more >Vulnerability Details : CVE-2021-23017
CVE-2021-23017 : A security issue in nginx resolver was identified, ... Product Type, Vendor, Product, Version, Update, Edition, Language.
Read more >Red Hat: CVE-2021-23017: Important: nginx:1.18 security ...
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS...
Read more >A new nginx package with the fix for the CVE-2021-23017 ...
A new nginx package with the fix for the CVE-2021-23017 within CentOS 6 ELS has been scheduled for gradual rollout.
Read more >NGINX Plus and Open Source vulnerability CVE-2021 ... - AskF5
Versions using NGINX Open Source: 1.0.0 - 1.11.2, 1.11.3 ... The Upgrading NGINX Plus section of the NGINX Admin Guide; The NGINX Ingress ......
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Looks like it is indeed: https://metadata.ftp-master.debian.org/changelogs//main/n/nginx/nginx_1.14.2-2+deb10u4_changelog
https://github.com/jitsi/docker-jitsi-meet/releases/tag/stable-5963 is out.