Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2024-23828
Summary
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via a CRLF attack when changing the value of "test_config_cmd" or "start_cmd". This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This issue affects versions v2.0.0-beta.5-patch through 2.0.0-beta.11.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-74 - Injection
Listed as the number one web application security risk on the 'OWASP Top Ten', injection attacks are widespread and dangerous, especially in legacy applications. Injection attacks are a class of vulnerabilities in which an attacker injects untrusted data into a web application that gets processed by an interpreter, altering the program's execution. This can result in data loss/theft, loss of data integrity, denial of service, and even compromising the entire system.
References
Advisory Timeline
- Published