PT-2024-7510 · Nginx · Nginx-Ui

Unam4

·

Published

2024-10-09

·

Updated

2024-11-11

·

CVE-2024-49367

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Nginx UI versions prior to 2.0.0-beta.36
Description: The issue is related to the configuration settings of the Nginx UI server, specifically the /api/configs directory, and is associated with weaknesses in the authorization procedure. This can be combined with directory traversal to read directories and file contents on the server.
Recommendations: For versions prior to 2.0.0-beta.36, update to version 2.0.0-beta.36 to fix the issue. As a temporary workaround, consider restricting access to the /api/configs API endpoint until a patch is available.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-08899
CVE-2024-49367
GHSA-GR34-JGW4-7J4M

Affected Products

Nginx-Ui