CVE-2022-31125

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
06/07/2022
Last modified:
03/04/2023

Description

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:* 6.1.1.0 (excluding)