You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi,
We see that the CVE-2023-44487 is now being reported for the latest release of nginx-s3-gateway docker image in our security scan tool and were wondering if there is any configuration that can be used to fix or mitigate the vulnerability.
The text was updated successfully, but these errors were encountered:
As for this container image, it is not running in HTTP/2 mode by default. Additionally, with NGINX's default keepalive limit it is not affected by the type of attack detailed in the CVE. However, I believe that the latest NGINX version has added additional protections.
@4141done Can you look into upgrading the default NGINX version in the Dockerfile(s) as well as bumping the njs version?
Hi,
We see that the CVE-2023-44487 is now being reported for the latest release of nginx-s3-gateway docker image in our security scan tool and were wondering if there is any configuration that can be used to fix or mitigate the vulnerability.
The text was updated successfully, but these errors were encountered: