PT-2024-7289 · Nginx · Nginx-Ui

·

CVE-2024-49368

·

Published

2024-10-14

·

Updated

2024-11-06

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Nginx UI versions prior to 2.0.0-beta.36
Description: The issue is related to the Nginx UI's configuration of logrotate, where it does not verify input and directly passes it to exec.Command, causing arbitrary command execution. This allows a remote attacker to execute arbitrary commands.
Recommendations: For versions prior to 2.0.0-beta.36, update to version 2.0.0-beta.36 to secure your Nginx web server. As a temporary workaround, consider restricting access to the logrotate configuration to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08643
CVE-2024-49368
GHSA-66M6-27R9-77VM

Affected Products

Nginx-Ui