Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.
References
Link | Resource |
---|---|
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-xvq9-4vpv-227m | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-01-29 16:15
Updated : 2024-02-08 16:42
NVD link : CVE-2024-23827
Mitre link : CVE-2024-23827
CVE.ORG link : CVE-2024-23827
JSON object : View
Products Affected
nginxui
- nginx_ui
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')