Jump to content

CVE-2016-2183 vulnerability detected on Central Node v4.0 [KATA/KEDRE]


Recommended Posts

Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.

You can receive vulnerability CVE-2016-2183 alerts while scanning Central Node v4.0 with the following insecure cipher suites:

* TLS 1.2 ciphers: * TLS_RSA_WITH_3DES_EDE_CBC_SHA

Clarifications:

Here are more details on CVE-2016-2183.

Fix:

Fix download link. 

1) docker load < /path/to/container/nginx_gateway-4.0-pf1

2) Change container's version in /etc/opt/kaspersky/apt-swarm/image_versions.json
    put:
    "nginx_gateway": "registry.kata.avp.ru:5000/kaspersky/kata/web/nginx_gateway:aa48c91",

3) Load new container:
docker service update kataedr_main_1_nginx_gateway --image "registry.kata.avp.ru:5000/kaspersky/kata/web/nginx_gateway:aa48c91"

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...