Share via

PCI scan failing on Azure Web App

Jason Dean 6 Reputation points
2021-08-13T13:03:00.55+00:00

Hi,

We are getting a failed PCI scan reporting multiple issues with NGINX. There is literally nothing on the internet about how to fix this. PCI Compliance Manager wants us to upgrade the version of NGINX that Azure is using but I'm not sure we can even do that. See error message below. What do I do to make this scan pass? The web app that it's scanning is just a simple website or Azure App Service (xyz.azurewebsites.net).

Vulnerable nginx version detected on port 80 -
Server: nginx/1.16.1

CVE-2019-20372
CVE-2021-23017

Customers are advised to install nginx 1.21.0 or later versions to remediate this vulnerability.

Azure App Service
Azure App Service

Azure App Service is a service used to create and deploy scalable, mission-critical web apps.

{count} votes

1 answer

Sort by: Most helpful
  1. Jason Dean 6 Reputation points
    2021-08-19T21:03:46.967+00:00

    Just to close the loop on this issue... I ended up having to create a new App Service and port the app over to that. I re-ran the PCI scan and everything is good.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.