jdauphant / ansible-role-nginx

Ansible role to install and manage nginx configuration
655 stars 302 forks source link

CVE 2016-1247 #174

Closed teadur closed 7 years ago

teadur commented 7 years ago

According to CVE-2016-1247 /var/log/nginx shouldnot be owned by www-data Not sure if that patch brakes it for other distros, only tested on debian.

more info: https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html