← Back

CVE-2024-49366

nvd nist
Published: Oct 21, 2024Modified: Nov 7, 2024

JSON object

Loading...
7.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security-advisories@github.com (Secondary)

Description

Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26 fixes the issue.

Affected (49)

Products: Nginxui: Nginx Ui
1 product
Nginx Ui
Configuration A
49 vulnerable
Vulnerable SoftwareAffected Versions
Nginxui
Up to 1.9.9-4
Version 2.0.0 beta10
Version 2.0.0 beta10_patch
Version 2.0.0 beta11
Version 2.0.0 beta12
Version 2.0.0 beta13-patch
Version 2.0.0 beta13
Version 2.0.0 beta14
Version 2.0.0 beta15
Version 2.0.0 beta16
Version 2.0.0 beta17
Version 2.0.0 beta18-patch1
Version 2.0.0 beta18-patch2
Version 2.0.0 beta18
Version 2.0.0 beta19
Version 2.0.0 beta1
Version 2.0.0 beta20
Version 2.0.0 beta21
Version 2.0.0 beta22
Version 2.0.0 beta23-patch1
Version 2.0.0 beta23-ptach2
Version 2.0.0 beta23
Version 2.0.0 beta24
Version 2.0.0 beta25-patch1
Version 2.0.0 beta25-ptach2
Version 2.0.0 beta25
Version 2.0.0 beta27
Version 2.0.0 beta28
Version 2.0.0 beta29
Version 2.0.0 beta2
Version 2.0.0 beta30
Version 2.0.0 beta31
Version 2.0.0 beta32-patch1
Version 2.0.0 beta32
Version 2.0.0 beta33
Version 2.0.0 beta34
Version 2.0.0 beta35
Version 2.0.0 beta3
Version 2.0.0 beta4
Version 2.0.0 beta4_patch
Version 2.0.0 beta5
Version 2.0.0 beta5_patch
Version 2.0.0 beta6
Version 2.0.0 beta6_patch2
Version 2.0.0 beta6_patch
Version 2.0.0 beta7
Version 2.0.0 beta8
Version 2.0.0 beta8_patch
Version 2.0.0 beta9

References (2)

Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.