CVE-2024-22198
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
Record summary
CVE-2024-22198 has a selected CVSS score of 7.1 (high); EIP currently links 1 repository PoC.
Description
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow users to modify the `Terminal Start Command` setting, it is possible to do so by sending a request to the API. This issue may lead to authenticated remote code execution, privilege escalation, and information disclosure. This vulnerability has been patched in version 2.0.0.beta.9.
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 1, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
nginx-uiBrowse 0xJacky / nginx-ui | CVE List | < 2.0.0.beta.9 | affected |
nginx_uiBrowse nginxui / nginx_uiDefault status: unknown | CVE List | Before 2.0.0.beta.8 | affected |
| 2.0.0 | unaffected | ||
github.com/0xJacky/Nginx-UIBrowse Go / github.com/0xJacky/Nginx-UI | GitHub Advisory | Before 1.9.10-0.20231219184941-827e76c46e63 · Fixed in 1.9.10-0.20231219184941-827e76c46e63 | affected |