Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0460 Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.
Github GHSA Github GHSA GHSA-xvq9-4vpv-227m Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 12 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-12T21:41:24.606Z

Reserved: 2024-01-22T22:23:54.338Z

Link: CVE-2024-23827

cve-icon Vulnrichment

Updated: 2024-08-01T23:13:08.227Z

cve-icon NVD

Status : Modified

Published: 2024-01-29T16:15:09.867

Modified: 2024-11-21T08:58:30.357

Link: CVE-2024-23827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.