bcgov / bcgov/foi-flow

[ACS Report] Upgrade nginx from 1.17 to 1.25.3

Open
#4,977 1 comment 0 reactions 0 assignees View on GitHub
high priority security
Dominant language
Python
Stars
8
Forks
2
Avg merge
14h 34m
Merged PRs (30d)
46

Description

w.r.t Recent security exploitation around HTTP2. It is highly recommended to upgrade to latest version 1.25.3

Reference:
https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/

**Impacted components:
request-management-api**

ACS:
https://acs.developer.gov.bc.ca/main/violations/1bb73570-f024-496b-8ff5-2ef418ec66a2

Contributor guide

Open the contributing guide

Research direction

Start with the request-management-api component and identify where its nginx version is declared. Review the linked CISA and F5 references for the HTTP/2 Rapid Reset concern, then verify that the deployed nginx version is 1.25.3 or later and that the component still builds and runs.

Written by the indexing model from the issue text.

Assessment

Tech stack
nginx
Domain
infrastructure, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.