Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

0day security issue #244

Closed
chamba opened this issue Apr 2, 2018 · 1 comment
Closed

0day security issue #244

chamba opened this issue Apr 2, 2018 · 1 comment
Labels
3sp paquetización seguridad Issues relativos a la seguridad de la aplicación.

Comments

@chamba
Copy link

chamba commented Apr 2, 2018

La version de Nginx que usan es vulnerable a una falla de tipo RCO con exploit publico, nixawk/labs#15. Tienen que actualizar la versión de Nginx

Ademas están filtrando la version del server que usan en varios lugares, deberían remover esa información.

HTTP/1.1 400 Bad Request
Content-Type: application/json
Content-Length: 90
Connection: close
X-RateLimit-Limit-hour: 10000
X-RateLimit-Remaining-hour: 9996
X-RateLimit-Limit-second: 5
X-RateLimit-Remaining-second: 3
Server: nginx/1.10.3 (Ubuntu)
Date: Mon, 02 Apr 2018 18:26:41 GMT
X-Frame-Options: SAMEORIGIN
Access-Control-Allow-Origin: *
X-Kong-Upstream-Latency: 26
X-Kong-Proxy-Latency: 2
Via: kong/0.11.2

{"errors": [{"error": "Par\u00e1metro format inv\u00e1lido: <built-in function format>"}]}

[email protected]
[email protected]

@abenassi abenassi added búsqueda paquetización seguridad Issues relativos a la seguridad de la aplicación. labels Apr 3, 2018
@abenassi abenassi added to do and removed búsqueda labels Apr 18, 2018
@lucaslavandeira
Copy link
Contributor

Gracias por notificarnos! Ya tomamos las medidas necesarias y próximamente se deployará el fix a los servidores productivos

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3sp paquetización seguridad Issues relativos a la seguridad de la aplicación.
Projects
None yet
Development

No branches or pull requests

4 participants