Description
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0460 | Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue. |
Github GHSA |
GHSA-xvq9-4vpv-227m | Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature |
References
History
Tue, 12 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-12T21:41:24.606Z
Reserved: 2024-01-22T22:23:54.338Z
Link: CVE-2024-23827
Updated: 2024-08-01T23:13:08.227Z
Status : Modified
Published: 2024-01-29T16:15:09.867
Modified: 2024-11-21T08:58:30.357
Link: CVE-2024-23827
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA