By using AWS re:Post, you agree to the Terms of Use
/Is nginx on Elastic Beanstalk vulnerable to 1-byte memory overwrite?/

Is nginx on Elastic Beanstalk vulnerable to 1-byte memory overwrite?

0

We are working with a cybersecurity group to improve our overall cybersecurity on our applications. They have identified a possible problem on our Elastic Beanstalk environments. Even though they are up-to-deate as far as platform version goes on a currently supported platform (Ruby 2.7 Linux 2 with the latest version), they appear to run nginx 1.20.0. nginx 1.20.1 fixes the security vulnerability in question.

Is there a reasonable way for us to force usage of nginx 1.20.2? Absent that, any suggestions on how to remediate this issue?

1 Answers
0

So after further research, I am 95% sure that despite vulnerability scans showing that the instances are simply running nginx 1.20.0, they are in fact running release 2.amzn2.0.4 of nginx 1.20.0. The vulnerability was patched in release 2.amzn2.0.3. The problem remains getting the security scan to accept this. One solution found is detailed here - https://github.com/aws/elastic-beanstalk-roadmap/issues/194 - essentially force an install of nginx 1.20.1 (or 1.20.2).

answered 4 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions