This archive is retained to ensure existing URLs remain functional. It will not contain any emails sent to this mailing list after July 1, 2024. For all messages, including those sent before and after this date, please visit the new location of the archive at https://mailman.ripe.net/archives/list/[email protected]/
[atlas] RIPE Anchor updates?
- Previous message (by thread): [atlas] Probe DHCPv6 support
- Next message (by thread): [atlas] RIPE Anchor updates?
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
John Howard
john.howard at proton.ch
Tue May 16 12:42:13 CEST 2023
Hi folks, Proton hosts 3 RIPE Anchors (7120, 6847, 6854) and during routine vulnerability scanning we identified these appliances running nginx 1.20.1, which is potentially vulnerable to two CVEs (CVE-2022-41741 and CVE-2022-41742). Given the mp4 module pre-req, I doubt they are vulnerable in practice, but this highlighted that the nginx 1.20 train was deprecated 11 months ago, and 1.23/1.24 are the currently active releases. I note the last probe firmware update 5080 (which we run already) from Nov/22 disabled auto updates on the appliances, so I assume there will be regular updates coming from RIPE going forward instead? Thanks John -- John Howard Head of Network Infrastructure Proton AG Sent with Proton Mail secure email. -------------- next part -------------- An HTML attachment was scrubbed... URL: </ripe/mail/archives/ripe-atlas/attachments/20230516/140f930d/attachment.html> -------------- next part -------------- A non-text attachment was scrubbed... Name: publickey - john.howard at proton.ch - 0x90E7CFE6.asc Type: application/pgp-keys Size: 657 bytes Desc: not available URL: </ripe/mail/archives/ripe-atlas/attachments/20230516/140f930d/attachment.bin> -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 249 bytes Desc: OpenPGP digital signature URL: </ripe/mail/archives/ripe-atlas/attachments/20230516/140f930d/attachment.sig>
- Previous message (by thread): [atlas] Probe DHCPv6 support
- Next message (by thread): [atlas] RIPE Anchor updates?
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]