CVE-2024-23828
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
29/01/2024
Last modified:
08/02/2024
Description
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been patched in version 2.0.0.beta.12.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* | 2.0.0 (excluding) | |
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta10:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta10_patch:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta11:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta4_patch:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta5_patch:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6_patch:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6_patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



