CVE-2024-22196
11.01.2024, 20:15
Nginx-UI is an online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"` and `"id"` values are used as default values if the query parameters are not set. Thus, the `order` and `sort_by` query parameter are user-controlled and are being appended to the `order` variable without any sanitization. This issue has been patched in version 2.0.0.beta.9.
Vendor | Product | Version |
---|---|---|
nginxui | nginx_ui | 𝑥 < 2.0.0 |
nginxui | nginx_ui | 2.0.0:beta1 |
nginxui | nginx_ui | 2.0.0:beta2 |
nginxui | nginx_ui | 2.0.0:beta3 |
nginxui | nginx_ui | 2.0.0:beta4 |
nginxui | nginx_ui | 2.0.0:beta4_patch |
nginxui | nginx_ui | 2.0.0:beta5 |
nginxui | nginx_ui | 2.0.0:beta5_patch |
nginxui | nginx_ui | 2.0.0:beta6 |
nginxui | nginx_ui | 2.0.0:beta6_patch |
nginxui | nginx_ui | 2.0.0:beta6_patch2 |
nginxui | nginx_ui | 2.0.0:beta7 |
nginxui | nginx_ui | 2.0.0:beta8 |
nginxui | nginx_ui | 2.0.0:beta8_patch |
𝑥
= Vulnerable software versions
References