CVE-2021-23017 issue for services running behind Network load balancer

0

We have a couple of services running on EKS fargate accessible from internet via network load balancers.

We have recently conducted external penetration testing as part of our compliance process. It identified that the network load balancer is using nginx v1.20 which is subject to a security issue CVE-2021-23017 https://alas.aws.amazon.com/cve/html/CVE-2021-23017.html#score-breakdown . This issue has been fixed in v1.20.1.

Is there a patch that has been applied to network load balancer to fix CVE-2021-23017 or any mitigation we can do to overcome this from client (our) side?

Could anyone provide any pointers for me to gather more information in order to make an assessment of the severity level?

I searched the forum but only found a few posts about this issue with regards to elastic beanstalk, nothing about the network load balancer.

Thank you.

Edited by: yybc9a3 on Nov 26, 2021 3:27 AM

Edited by: yybc9a3 on Nov 26, 2021 3:31 AM

yybc9a3
질문됨 2년 전304회 조회
1개 답변
0

Turned out that it was a massive overlook.... We did run a small nginx container after netwrok load balancer....
Problem solved.

Edited by: yybc9a3 on Nov 26, 2021 6:24 AM

yybc9a3
답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠