Apache and OpenSSL running on its EC2 instances bundled with RedHat Linux 8 are outdated, how to best resolve this

0

As part of the System Penetration results, customer was advised that the versions of Apache and OpenSSL running on its EC2 instances bundled with RedHat Linux 8 are outdated and need to be updated to the latest version as they are vulnerable to several security vulnerabilities that might lead to system compromise according to penetration test outcomes. However, customer's Managed Service Partner advised that these versions that come with RedHat package updates are the latest ones that are compatible with the version of RedHat Kernel, and it would not be a good idea to manually upgrade these to the mainstream versions.

The customer would like to know the best way to resolve this issue?

1개 답변
0

I would snapshot the existing instance, spin up a new instance with that snapshot, and then upgrade the packages. Then test.

If you are behind a ALB, you could create a canary with the updated package and use weighted target groups to send a small amount of traffic to the canary.

profile pictureAWS
전문가
kentrad
답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠