Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nginx 0.6.x < 1.20.1 1-Byte Memory Overwrite RCE vulnerability #230

Open
lions1988 opened this issue Jan 23, 2024 · 2 comments
Open

nginx 0.6.x < 1.20.1 1-Byte Memory Overwrite RCE vulnerability #230

lions1988 opened this issue Jan 23, 2024 · 2 comments

Comments

@lions1988
Copy link

lions1988 commented Jan 23, 2024

Hey team

Our Nesssus scanners detected the following vulnerability on ClearML containers (apiserver, fileserver and webserver)
ClearML versions: WebApp: 1.14.0-431 • Server: 1.14.0-431 • API: 2.28
Nessus plugin: https://www.tenable.com/plugins/nessus/150154
Existing nginx version:

docker exec -ti clearml-apiserver nginx -v
nginx version: nginx/1.18.0

Please advice
Thank you

@jkhenning
Copy link
Member

Hi @lions1988,

Thanks for bringing it to our attention. We'll upgrade to nginx 1.23 in the upcoming release.

@pollfly
Copy link
Contributor

pollfly commented Mar 28, 2024

Hey @lions1988! Just letting you know that this issue has been resolved in the recently released v1.15.0. Let us know if there are any issues :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants