PT-2024-7289 · Nginx · Nginx-Ui
0Xjacky
·
Published
2024-10-14
·
Updated
2024-11-06
·
CVE-2024-49368
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Nginx UI versions prior to 2.0.0-beta.36
Description:
The issue is related to the Nginx UI's configuration of logrotate, where it does not verify input and directly passes it to exec.Command, causing arbitrary command execution. This allows a remote attacker to execute arbitrary commands.
Recommendations:
For versions prior to 2.0.0-beta.36, update to version 2.0.0-beta.36 to secure your Nginx web server. As a temporary workaround, consider restricting access to the logrotate configuration to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx-Ui