NGINX
274 incident problems in NGINX environments.
먼저 읽을 가이드
추천 문제
All problems (274)
SECURITY-1593A WAF exception cleanup is correct and one hostname still skips inspectionOne hostname still skips inspection after WAF exception cleanup.SecurityAdvanced9 minProSECURITY-1563A managed WAF exception is removed and one hostname still skips inspectionOne hostname still skips WAF inspection after managed rules cleanup.SecurityAdvanced10 minProSECURITY-1573A WAF allowlist is cleaned up and one path still trusts the old CIDROne path still trusts the old CIDR after WAF allowlist cleanup.SecurityAdvanced10 minProSECURITY-1583A WAF exception is removed and one host still bypasses inspectionOne hostname still bypasses inspection after WAF exception cleanup.SecurityAdvanced10 minProSECURITY-1553A WAF managed rule exception is removed and one API still passes malicious payloadsMalicious payloads pass only on one hostname after managed rule cleanup.SecurityAdvanced11 minProSECURITY-1393An OpenSearch admin SSO flow returns successfully and session validation failsAn OpenSearch admin SSO flow returns successfully and session validation fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. JWT validation issues after key rotation often live in intermediate JWKS cache...SecurityAdvanced14 minProNETWORK-1351A Cloudflare Tunnel app stays reachable and WebSocket upgrades failA Cloudflare Tunnel app stays reachable and WebSocket upgrades fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Realtime failures behind proxies often come from route-specific header handling r...NetworkAdvanced15 minProSECURITY-1334A CrowdSec or Fail2ban style ban pipeline blocks the wrong sourceA CrowdSec or Fail2ban style ban pipeline blocks the wrong source focuses on incident-response and asks the reader to isolate the key signal in NGINX. Security controls that depend on source IP must be reviewed whenever the trust bo...SecurityAdvanced15 minProCICD-1364A private registry behind NGINX handles login and small layers fineA private registry behind NGINX handles login and small layers fine focuses on Artifact Promotion and asks the reader to isolate the key signal in NGINX. Path-specific protection can succeed on auth and manifest routes while silently breaking long-l...CI/CDAdvanced15 minProNETWORK-1339A Tunnel and WARP path look healthy and one internal app still failsA Tunnel and WARP path look healthy and one internal app still fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers can be lost after the edge if internal proxy routing is not exp...NetworkAdvanced15 minProSECURITY-1339A WAF challenge policy protects the main app and still exposes one admin routeA WAF challenge policy protects the main app and still exposes one admin route focuses on Deployment Governance and asks the reader to isolate the key signal in NGINX. Security includes can look global while still missing routes defined in separate...SecurityAdvanced15 minProNETWORK-1349An NGINX auth flow works for normal pages and Cloudflare Access headers...An NGINX auth flow works for normal pages and Cloudflare Access headers... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity loss behind a proxy often happens on local rewrites long after...NetworkAdvanced15 minProSECURITY-1372An OpenSearch dashboard SSO flow works on GET and failsAn OpenSearch dashboard SSO flow works on GET and fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Cross-site POST returns are especially sensitive to SameSite policy changes around proxy and...SecurityAdvanced15 minProSECURITY-098CloudFront signed cookie scope excludes the websocket upgrade host and only the browser terminal loses authStatic pages load normally, but the interactive browser tool fails because the signed cookie domain or path does not cover the upgraded endpoint host.SecurityAdvanced16 minProSECURITY-357A certificate replacement installs the right chainA certificate replacement installs the right chain focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 certificate-trust-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점...SecurityAdvanced17 minProSECURITY-387A mutual TLS edge validates the client certificateA mutual TLS edge validates the client certificate focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점의...SecurityAdvanced17 minProSECURITY-375A reverse proxy or isolation layer protects browser trafficA reverse proxy or isolation layer protects browser traffic focuses on WAF and AppSec Controls and asks the reader to isolate Permission Denied in NGINX. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. WAF / AppSec 관점...SecurityAdvanced17 minProSECURITY-105A WAF bypass exception for health checks accidentally matches the admin route prefix after a path refactorMonitoring stays green, but a protection hole opens because the relaxed path rule now overlaps with privileged endpoints.SecurityAdvanced17 minProSECURITY-143A WAF custom rule matches on decoded path segments, but the reverse proxy evaluates the raw form and one legacy route stays bypassableBoth layers inspect the request, yet they do not interpret the path in the same representation.SecurityAdvanced17 minProSECURITY-092Cloud WAF blocks the admin API path only after a new JSON field increases rule score above thresholdThe endpoint worked before, but the updated payload shape now trips a scoring-based rule model that was previously below the block threshold.SecurityAdvanced17 minPro