9.8

CVE-2024-23827

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NginxuiNginx Ui Version1.2.0 Update-
NginxuiNginx Ui Version1.2.0 Updatealpha2
NginxuiNginx Ui Version1.2.0 Updatealpha3
NginxuiNginx Ui Version1.2.0 Updatealpha4
NginxuiNginx Ui Version1.2.0 Updaterc1
NginxuiNginx Ui Version1.2.0 Updaterc2
NginxuiNginx Ui Version1.2.0 Updaterc3
NginxuiNginx Ui Version1.2.1
NginxuiNginx Ui Version1.2.2
NginxuiNginx Ui Version1.3.0 Update-
NginxuiNginx Ui Version1.3.0 Updaterc1
NginxuiNginx Ui Version1.3.1 Update-
NginxuiNginx Ui Version1.3.1 Updatefix
NginxuiNginx Ui Version1.3.2
NginxuiNginx Ui Version1.3.3 Updaterc1
NginxuiNginx Ui Version1.4.0 Update-
NginxuiNginx Ui Version1.4.0 Updaterc1
NginxuiNginx Ui Version1.4.1
NginxuiNginx Ui Version1.4.2
NginxuiNginx Ui Version1.5.0 Update-
NginxuiNginx Ui Version1.5.0 Updatebeta1
NginxuiNginx Ui Version1.5.0 Updatebeta2
NginxuiNginx Ui Version1.5.0 Updatebeta3
NginxuiNginx Ui Version1.5.0 Updatebeta4
NginxuiNginx Ui Version1.5.0 Updatebeta4_fix
NginxuiNginx Ui Version1.5.0 Updatebeta5
NginxuiNginx Ui Version1.5.0 Updatebeta6
NginxuiNginx Ui Version1.5.0 Updatebeta7
NginxuiNginx Ui Version1.5.0 Updatebeta8
NginxuiNginx Ui Version1.5.0 Updatebeta9
NginxuiNginx Ui Version1.5.1
NginxuiNginx Ui Version1.5.2
NginxuiNginx Ui Version1.6.0 Update-
NginxuiNginx Ui Version1.6.0 Updatefix
NginxuiNginx Ui Version1.6.1
NginxuiNginx Ui Version1.6.2
NginxuiNginx Ui Version1.6.3
NginxuiNginx Ui Version1.6.5
NginxuiNginx Ui Version1.6.6
NginxuiNginx Ui Version1.6.7
NginxuiNginx Ui Version1.6.8
NginxuiNginx Ui Version1.7.0 Update-
NginxuiNginx Ui Version1.7.0 Updatepatch
NginxuiNginx Ui Version1.7.1
NginxuiNginx Ui Version1.7.2
NginxuiNginx Ui Version1.7.3
NginxuiNginx Ui Version1.7.4
NginxuiNginx Ui Version1.7.5
NginxuiNginx Ui Version1.7.6
NginxuiNginx Ui Version1.7.7
NginxuiNginx Ui Version1.7.8
NginxuiNginx Ui Version1.7.9
NginxuiNginx Ui Version1.8.0
NginxuiNginx Ui Version1.8.1
NginxuiNginx Ui Version1.8.2
NginxuiNginx Ui Version1.8.3
NginxuiNginx Ui Version1.8.4 Update-
NginxuiNginx Ui Version1.8.4 Updatepatch
NginxuiNginx Ui Version1.9.9
NginxuiNginx Ui Version1.9.9-1
NginxuiNginx Ui Version1.9.9-2
NginxuiNginx Ui Version1.9.9-3
NginxuiNginx Ui Version1.9.9-4
NginxuiNginx Ui Version2.0.0 Updatebeta1
NginxuiNginx Ui Version2.0.0 Updatebeta10
NginxuiNginx Ui Version2.0.0 Updatebeta10_patch
NginxuiNginx Ui Version2.0.0 Updatebeta11
NginxuiNginx Ui Version2.0.0 Updatebeta2
NginxuiNginx Ui Version2.0.0 Updatebeta3
NginxuiNginx Ui Version2.0.0 Updatebeta4
NginxuiNginx Ui Version2.0.0 Updatebeta4_patch
NginxuiNginx Ui Version2.0.0 Updatebeta5
NginxuiNginx Ui Version2.0.0 Updatebeta5_patch
NginxuiNginx Ui Version2.0.0 Updatebeta6
NginxuiNginx Ui Version2.0.0 Updatebeta6_patch
NginxuiNginx Ui Version2.0.0 Updatebeta6_patch2
NginxuiNginx Ui Version2.0.0 Updatebeta7
NginxuiNginx Ui Version2.0.0 Updatebeta8
NginxuiNginx Ui Version2.0.0 Updatebeta8_patch
NginxuiNginx Ui Version2.0.0 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.97% 0.86
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.