Project

General

Profile

Actions

Bug #12061

closed

Update NGINX to address CVE-2021-23017

Added by Kris Phillips almost 3 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Category:
Operating System
Target version:
Start date:
06/18/2021
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
22.01
Release Notes:
Default
Affected Version:
Affected Architecture:
All

Description

https://vuxml.freebsd.org/freebsd/0882f019-bd60-11eb-9bdd-8c164567ca3c.html

NGINX needs to be updated to resolve this vulnerability

Actions #1

Updated by Jim Pingle almost 3 years ago

http://nginx.org/en/CHANGES shows it's fixed in 1.20.1, but 1.20.1 is not yet in the ports tree: https://github.com/freebsd/freebsd-ports/blob/main/www/nginx/Makefile

Actions #2

Updated by Renato Botelho almost 3 years ago

  • Status changed from New to Feedback
  • Assignee set to Renato Botelho

I've cherry-picked commits to upgrade it to 1.20.1,2 on RELENG_2_5_2. Development branches will get it on next round of merges from upstream

Actions #3

Updated by Jim Pingle almost 3 years ago

  • Subject changed from Update NGINX to Fix Vulnerability to Update NGINX to address CVE-2021-23017
  • Status changed from Feedback to Closed
  • Plus Target Version changed from Plus-Next to 21.09

nginx-1.20.1,2 is in the latest test build. GUI, XMLRPC, and captive portal are all working as expected.

While I'm here, update subject for the release notes.

Actions #4

Updated by Jim Pingle over 2 years ago

  • Category changed from Web Interface to Operating System
Actions #5

Updated by Jim Pingle over 2 years ago

  • Plus Target Version changed from 21.09 to 22.01
Actions

Also available in: Atom PDF