Description

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 2.0.0.beta.12affected

github.com/0xJacky/Nginx-UI

Browse Go / github.com/0xJacky/Nginx-UI
GitHub AdvisoryBefore 1.9.10-0.20240128060047-8581bdd3c6f4 · Fixed in 1.9.10-0.20240128060047-8581bdd3c6f4affected

References

6