9.8

CVE-2024-49368

Exploit

Unchecked logrotate settings lead to arbitrary command execution

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nginxui ≫ Nginx Ui Version <= 1.9.9-4
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta1
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta10
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta10_patch
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta11
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta12
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta13
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta13-patch
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta14
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta15
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta16
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta17
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta18
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta18-patch1
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta18-patch2
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta19
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta2
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta20
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta21
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta22
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta23
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta23-patch1
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta23-ptach2
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta24
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta25
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta25-patch1
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta25-ptach2
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta27
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta28
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta29
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta3
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta30
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta31
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta32
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta32-patch1
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta33
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta34
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta35
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta4
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta4_patch
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta5
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta5_patch
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta6
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta6_patch
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta6_patch2
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta7
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta8
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta8_patch
Nginxui ≫ Nginx Ui Version 2.0.0 Update beta9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 27.48% 0.979
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 8.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.36
Release Notes
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-66m6-27r9-77vm
Vendor Advisory
Exploit