AgainstTheWest / NginxDay

Nginx 18.1 04/09/22 zero-day repo
367 stars 34 forks source link

Update from nginx is available #3

Closed tweedge closed 2 years ago

tweedge commented 2 years ago

Hi! Looks like nginx has responded here if you wanted to analyze their claims or add the response to this repo: https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/

TL;DR nginx claims this is not an 0day in nginx itself, but acknowledges the security issue in a specific reference implementation.

Very conceivable that folks would deploy the reference implementation in their environment without RTFM or testing, of course. :grimacing:

tweedge commented 2 years ago

Closing as I see a reference to nginx's announcement was added in Update 7 around nine hours ago.