[GH-ISSUE #1011] OpenSSL Vulnerabilities - CVE-2021-3449 and CVE-2021-3450 #850

Closed
opened 2026-02-26 06:34:40 +03:00 by kerem · 2 comments
Owner

Originally created by @Wadera on GitHub (Apr 11, 2021).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/1011

Describe the bug

https://www.openssl.org/news/vulnerabilities.html

# docker-compose down && docker-compose up -d
# docker exec -it 673b6dcfa45a  /bin/bash
 _   _       _            ____                      __  __
| \ | | __ _(_)_ __ __  _|  _ \ _ __ _____  ___   _|  \/  | __ _ _ __   __ _  __ _  ___ _ __
|  \| |/ _` | | '_ \\ \/ / |_) | '__/ _ \ \/ / | | | |\/| |/ _` | '_ \ / _` |/ _` |/ _ \ '__|
| |\  | (_| | | | | |>  <|  __/| | | (_) >  <| |_| | |  | | (_| | | | | (_| | (_| |  __/ |
|_| \_|\__, |_|_| |_/_/\_\_|   |_|  \___/_/\_\\__, |_|  |_|\__,_|_| |_|\__,_|\__, |\___|_|
       |___/                                  |___/                          |___/
Version 2.7.1 (72ac549) 2020-11-18 23:10:17 AEST, OpenResty 1.15.8.3, Alpine 3.12.0, Kernel 5.4.103-1-pve

[root@docker-673b6dcfa45a:/app]# openssl version
OpenSSL 1.1.1g  21 Apr 2020

Expected behavior
Get OpenSSL 1.1.1k version or never.

Originally created by @Wadera on GitHub (Apr 11, 2021). Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/1011 **Describe the bug** https://www.openssl.org/news/vulnerabilities.html ``` # docker-compose down && docker-compose up -d # docker exec -it 673b6dcfa45a /bin/bash _ _ _ ____ __ __ | \ | | __ _(_)_ __ __ _| _ \ _ __ _____ ___ _| \/ | __ _ _ __ __ _ __ _ ___ _ __ | \| |/ _` | | '_ \\ \/ / |_) | '__/ _ \ \/ / | | | |\/| |/ _` | '_ \ / _` |/ _` |/ _ \ '__| | |\ | (_| | | | | |> <| __/| | | (_) > <| |_| | | | | (_| | | | | (_| | (_| | __/ | |_| \_|\__, |_|_| |_/_/\_\_| |_| \___/_/\_\\__, |_| |_|\__,_|_| |_|\__,_|\__, |\___|_| |___/ |___/ |___/ Version 2.7.1 (72ac549) 2020-11-18 23:10:17 AEST, OpenResty 1.15.8.3, Alpine 3.12.0, Kernel 5.4.103-1-pve [root@docker-673b6dcfa45a:/app]# openssl version OpenSSL 1.1.1g 21 Apr 2020 ``` **Expected behavior** Get OpenSSL 1.1.1k version or never.
kerem 2026-02-26 06:34:40 +03:00
  • closed this issue
  • added the
    stale
    bug
    labels
Author
Owner

@github-actions[bot] commented on GitHub (Mar 14, 2024):

Issue is now considered stale. If you want to keep it open, please comment 👍

<!-- gh-comment-id:1996245278 --> @github-actions[bot] commented on GitHub (Mar 14, 2024): Issue is now considered stale. If you want to keep it open, please comment :+1:
Author
Owner

@github-actions[bot] commented on GitHub (Apr 25, 2025):

Issue was closed due to inactivity.

<!-- gh-comment-id:2829221229 --> @github-actions[bot] commented on GitHub (Apr 25, 2025): Issue was closed due to inactivity.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nginx-proxy-manager-NginxProxyManager#850
No description provided.