A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 03 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
Weaknesses | CWE-89 | |
CPEs | cpe:2.3:a:nginxproxymanager:nginx_proxy_manager:2.11.3:*:*:*:*:*:*:* | |
Vendors & Products |
Nginxproxymanager
Nginxproxymanager nginx Proxy Manager |
|
Metrics |
cvssV3_1
|
Fri, 27 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-27T00:00:00
Updated: 2024-10-24T17:13:28.700519
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-46257
Vulnrichment
Updated: 2024-10-03T15:36:53.223Z
NVD
Status : Awaiting Analysis
Published: 2024-09-27T18:15:05.870
Modified: 2024-10-24T18:15:08.617
Link: CVE-2024-46257
Redhat
No data.