Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nginxWebUI runCmd 远程命令执行漏洞 #119

Closed
yurenzhen opened this issue Dec 7, 2023 · 1 comment
Closed

nginxWebUI runCmd 远程命令执行漏洞 #119

yurenzhen opened this issue Dec 7, 2023 · 1 comment

Comments

@yurenzhen
Copy link

https://avd.aliyun.com/detail?id=AVD-2023-1672641

严重 nginxWebUI runCmd 远程命令执行漏洞
CVE编号

N/A
利用情况

漏洞武器化
补丁情况

官方补丁
披露时间

2023-05-05
该漏洞已被黑客武器化,用于大规模蠕虫传播、勒索挖矿,建议您立即关注并修复。
漏洞描述
nginxWebUI 是一款 Nginx可视化配置管理工具。2023年国内安全社区披露其存在权限绕过与后台命令执行漏洞,攻击者可在无需登录的情况下绕过路由权限校验,执行任意命令,控制服务器。
解决建议
利用安全组功能设置 nginxWebUI 仅对可信地址开放。

@cym1102
Copy link
Owner

cym1102 commented Dec 8, 2023 via email

@cym1102 cym1102 closed this as completed Feb 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants