summaryrefslogtreecommitdiff
path: root/.github/workflows/data-update.yml
diff options
context:
space:
mode:
authorAlex Balgavy <alex@balgavy.eu>2021-03-03 12:21:06 +0100
committerAlex Balgavy <alex@balgavy.eu>2021-03-03 12:34:22 +0100
commit6b59800dc65fed855ecfdeb9fe40a37807ecfeb9 (patch)
tree857f02b3262c3a2101afb05fbd81539748b04c54 /.github/workflows/data-update.yml
parentc748fc66cf7c4a4ebfecde61dd683422dd6b3901 (diff)
Fix security vulnerabilities in suggested nginx configuration
The suggested configurations for nginx found in the documentation and templates lead to vulnerabilities allowing host spoofing [1] and path traversal [2], as reported by Gixy [3]. This commit fixes those issues. [1] https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md [2] https://github.com/yandex/gixy/blob/master/docs/en/plugins/aliastraversal.md [3] https://github.com/yandex/gixy
Diffstat (limited to '.github/workflows/data-update.yml')
0 files changed, 0 insertions, 0 deletions