// For flags

CVE-2024-23828

Nginx-UI authenticated RCE through injecting into the application config via CRLF

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been patched in version 2.0.0.beta.12.

Nginx-UI es una interfaz web para administrar configuraciones de Nginx. Es vulnerable a la ejecución de un comando arbitrario autenticado mediante un ataque CRLF al cambiar el valor de test_config_cmd o start_cmd. Esta vulnerabilidad existe debido a una solución incompleta para CVE-2024-22197 y CVE-2024-22198. Esta vulnerabilidad ha sido parcheada en la versión 2.0.0.beta.12.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2024-01-22 CVE Reserved
  • 2024-01-29 CVE Published
  • 2024-02-08 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
< 2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version " < 2.0.0"
-
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta1
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta10
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta10_patch
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta11
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta2
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta3
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta4
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta4_patch
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta5
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta5_patch
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta6
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta6_patch
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta6_patch2
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta7
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta8
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta8_patch
Affected
Nginxui
Search vendor "Nginxui"
Nginx Ui
Search vendor "Nginxui" for product "Nginx Ui"
2.0.0
Search vendor "Nginxui" for product "Nginx Ui" and version "2.0.0"
beta9
Affected