GHSA-qcjq-7f7v-pvc8HighCVSS 8.8
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF
🔗 CVE IDs covered (1)
📋 Description
Summary
Fix bypass to the following bugs
- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-pxmr-q2x3-9x9m
- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-8r25-68wm-jw35
Allowing to inject directly in the app.ini via CRLF to change the value of test_config_cmd and start_cmd resulting in an Authenticated RCE
Impact
Authenticated Remote execution on the host
🎯 Affected products1
- go/github.com/0xJacky/Nginx-UI:< 1.9.10-0.20240126104956-d70e37c8575e