Skip to content

CVE-2023-44487 in latest image #182

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
saipraveen88 opened this issue Oct 19, 2023 · 1 comment · Fixed by #184
Closed

CVE-2023-44487 in latest image #182

saipraveen88 opened this issue Oct 19, 2023 · 1 comment · Fixed by #184

Comments

@saipraveen88
Copy link

saipraveen88 commented Oct 19, 2023

Hi,
We see that the CVE-2023-44487 is now being reported for the latest release of nginx-s3-gateway docker image in our security scan tool and were wondering if there is any configuration that can be used to fix or mitigate the vulnerability.

@dekobon
Copy link
Collaborator

dekobon commented Oct 24, 2023

Hi there,

My apologies for the late response. I believe this CVE is referencing HTTP/2 stream reset attacks. NGINX has a detailed blog post regarding the vulnerability here: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/

As for this container image, it is not running in HTTP/2 mode by default. Additionally, with NGINX's default keepalive limit it is not affected by the type of attack detailed in the CVE. However, I believe that the latest NGINX version has added additional protections.

@4141done Can you look into upgrading the default NGINX version in the Dockerfile(s) as well as bumping the njs version?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants