Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Update Cache and Message Relay - Multiple security vulnerabilities

Our network runs Sophos Endpoint clients using an Update Cache and Message Relay server. We've recently run a security audit and discovered the Update Cache server has multiple security vulnerabilities.

The Sophos Update Cache security vulnerabilities include:

  • Apache 2.4.37, which has a dozen or so vulnerabilities, rating from important to moderate to low.
  • HTTP TRACE/TRACK method enabled - this is for debugging purposes and considered a security risk in a production environment.

Is there documentation from Sophos on how to mitigate these vulnerabilities, or plans to release an update with them corrected?

References

Apache HTTP Server 2.4 vulnerabilities

https://httpd.apache.org/security/vulnerabilities_24.html

Apache Cross-Site Tracing issues

http://www.apacheweek.com/issues/03-01-24



This thread was automatically locked due to age.
Parents Reply Children
No Data