PT-2022-20576 · Haproxy+3 · Haproxy+3

Aidaho12

+1

·

Published

2022-07-15

·

Updated

2025-05-26

·

CVE-2022-31161

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 6.1.1.0
Description Roxy-WI is a Web interface for managing HAProxy, Nginx, and Keepalived servers. The system command can be run remotely via the subprocess execute function without processing the inputs received from the user in the /app/options.py file.
Recommendations For versions prior to 6.1.1.0, update to version 6.1.1.0 to resolve the issue. As a temporary workaround, consider disabling the subprocess execute function until a patch is available. Restrict access to the /app/options.py file to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Code Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31161
GHSA-PG3W-8P63-X483

Affected Products

Haproxy
Keepalived
Nginx
Roxy-Wi