Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nginx vulnerabilities #420

Open
rvanheesbyon opened this issue Oct 14, 2024 · 3 comments
Open

nginx vulnerabilities #420

rvanheesbyon opened this issue Oct 14, 2024 · 3 comments

Comments

@rvanheesbyon
Copy link

rvanheesbyon commented Oct 14, 2024

Hi Phusion,

Our security scans have found several vulnerabilities related to nginx 1.18, which is installed in the passenger/nodejs image. As this is used in our production image, we need a fast solution for this. I'd like to request an updated image using nginx >=1.24.

Thanks!
Richard

@ajhodgson
Copy link
Contributor

The fixes for all those CVEs have been backported by Ubuntu into the Jammy release of nginx 1.18 (where needed). Jammy will continue to receive regular security updates until April 2027.

@ajhodgson
Copy link
Contributor

Oh and apparently Cam just merged #413 which will update the source image to one based on Noble, which does contain nginx 1.24. So whenever that gets a release.

@rvanheesbyon
Copy link
Author

That's great, thanks for the update!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants