[ACS Report] Upgrade nginx from 1.17 to 1.25.3
- Dominant language
- Python
- Stars
- 8
- Forks
- 2
- Avg merge
- 14h 34m
- Merged PRs (30d)
- 46
Description
w.r.t Recent security exploitation around HTTP2. It is highly recommended to upgrade to latest version 1.25.3
Reference:
https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487
https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/
**Impacted components:
request-management-api**
ACS:
https://acs.developer.gov.bc.ca/main/violations/1bb73570-f024-496b-8ff5-2ef418ec66a2
Contributor guide
Research direction
Start with the request-management-api component and identify where its nginx version is declared. Review the linked CISA and F5 references for the HTTP/2 Rapid Reset concern, then verify that the deployed nginx version is 1.25.3 or later and that the component still builds and runs.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nginx
- Domain
- infrastructure, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100