Network Management

 View Only
  • 1.  Central On Prem - nginx upgrade

    Posted Nov 08, 2021 08:56 AM
    Hello,

    COP has been highlighted as having a high severity security issue by the scanning software we (the university) uses, it suggests upgrading nginx to mitigate the issue:

    High

    127907

    nginx 1.9.5 < 1.16.1 / 1.17.x < 1.17.3 Multiple Vulnerabilities


    We're running 2.5.3.3. Is this considered to be an issue? Will it be resolved in future releases?

    Many thanks,

    Guy



    ------------------------------
    Guy Goodrick
    ------------------------------


  • 2.  RE: Central On Prem - nginx upgrade

    Posted Nov 08, 2021 11:29 AM
    Please upgraded the COP setup to 2.5.3.5. The nginx is updated to 1.19 in 2.5.3.5 version.

    ------------------------------
    Gowri Sankar Amujuri
    ------------------------------



  • 3.  RE: Central On Prem - nginx upgrade

    Posted Nov 08, 2021 11:39 AM
    Edited by cauliflower Nov 08, 2021 11:44 AM
    Hello Gowri,

    Thanks for your reply. The recommended version according to the reporting tool is nginx 1.20.1. I guess as long as the most critical vulnerabilities are covered in 1.19 that should be ok. We'll attempt that. Thank you.

    Guy


    ------------------------------
    Guy Goodrick
    ------------------------------