CVE-2024-49366
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
21/10/2024
Last modified:
07/11/2024
Description
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26 fixes the issue.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:* | 1.9.9-4 (including) | |
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta10:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta10_patch:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta11:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta12:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta13:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta13-patch:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta14:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta15:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta16:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta17:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta18:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta18-patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta18-patch2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



