Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF
Package
Affected versions
< 2.0.0-beta.12
Patched versions
2.0.0-beta.12
Description
Published by the National Vulnerability Database
Jan 29, 2024
Published to the GitHub Advisory Database
Jan 29, 2024
Reviewed
Jan 29, 2024
Last updated
Aug 7, 2024
Summary
Fix bypass to the following bugs
Allowing to inject directly in the
app.ini
via CRLF to change the value oftest_config_cmd
andstart_cmd
resulting in an Authenticated RCEImpact
Authenticated Remote execution on the host
References