All incidents

Nginx Web Root Configuration Issue

Summary

/etc/nginx/conf.d/default.conf
/etc/nginx/conf.d/passbolt_ssl.conf
root /var/www/passbolt;
root /var/www/passbolt/webroot;
  • CVE: N/A.
  • Product affected: Passbolt Docker CE / PRO prior v2.5. Passbolt Pro VM and installation scripts.
  • Version affected: v2.0.4 and below
  • Version fixed: v2.0.5.
  • Affected component: Nginx configuration.
  • Vulnerability Type: Configuration Vulnerability.
  • Severity: High (CVSS 7.5).

Attack vector / exploitation

Other information

How did you find out about it?

I am using apache am I affected?

Do I need to change my server keys?

Event timeline

  • 2018-05-08 23:00 CET: Vulnerability details found during a routine check as part of v2.0.5 release.
  • 2018-05-08 09:00 PM CET: We deploy a new configuration file on CE/PRO VM, Docker containers.
  • 2018-05-09 19:00 PM CET: We publish this notice and update the release notes with this report

Current status:

Last updated: 2018-05-09 12:00 PM CET
Flag of European UnionMade in Europe. Privacy by default.