bcgov / foi-flow

Freedom of Information modernization
Apache License 2.0
4 stars 3 forks source link

[ACS Report] Upgrade nginx from 1.17 to 1.25.3 #4977

Open sumathi-thirumani-aot opened 6 months ago

sumathi-thirumani-aot commented 6 months ago

w.r.t Recent security exploitation around HTTP2. It is highly recommended to upgrade to latest version 1.25.3

Reference: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/

Impacted components: request-management-api

ACS: https://acs.developer.gov.bc.ca/main/violations/1bb73570-f024-496b-8ff5-2ef418ec66a2

sumathi-thirumani-aot commented 5 months ago

Internal Technical Refinement (4977):

Estimate: 3