MEDIUM
Nginx UI's log path can be controlled
Published Oct 21, 2024
5.5
MEDIUMCVSS 4.0
EPSS 0.64%
Description
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue.
Affected products
-
- Version < 2.0.0-beta.36StatusaffectedConstraints-
- Version
OR
- ≤ 1.9.9-4
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
-
- Version 0StatusaffectedConstraints<2.0.0-beta.36
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.36 x_refsource_MISCRelease Notes
- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-gr34-jgw4-7j4m x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/0xJacky/nginx-ui/releases/tag/v2.0.0-beta.36 | x_refsource_MISCRelease Notes | |
| https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-gr34-jgw4-7j4m | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 21, 2024
Updated Oct 21, 2024
Reserved Oct 14, 2024
Link CVE-2024-49367
CISA Vulnrichment
Updated Oct 21, 2024