CVE-2024-23828
29.01.2024, 17:15
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been patched in version 2.0.0.beta.12.
Vendor | Product | Version |
---|---|---|
nginxui | nginx_ui | 𝑥 < 2.0.0 |
nginxui | nginx_ui | 2.0.0:beta1 |
nginxui | nginx_ui | 2.0.0:beta10 |
nginxui | nginx_ui | 2.0.0:beta10_patch |
nginxui | nginx_ui | 2.0.0:beta11 |
nginxui | nginx_ui | 2.0.0:beta2 |
nginxui | nginx_ui | 2.0.0:beta3 |
nginxui | nginx_ui | 2.0.0:beta4 |
nginxui | nginx_ui | 2.0.0:beta4_patch |
nginxui | nginx_ui | 2.0.0:beta5 |
nginxui | nginx_ui | 2.0.0:beta5_patch |
nginxui | nginx_ui | 2.0.0:beta6 |
nginxui | nginx_ui | 2.0.0:beta6_patch |
nginxui | nginx_ui | 2.0.0:beta6_patch2 |
nginxui | nginx_ui | 2.0.0:beta7 |
nginxui | nginx_ui | 2.0.0:beta8 |
nginxui | nginx_ui | 2.0.0:beta8_patch |
nginxui | nginx_ui | 2.0.0:beta9 |
𝑥
= Vulnerable software versions