QID 996667

Date Published: 2024-01-15

QID 996667: GO (Go) Security Update for github.com/0xJacky/Nginx-UI (GHSA-pxmr-q2x3-9x9m)

The Home > Preference page exposes a small list of nginx settings such as Nginx Access Log Path and Nginx Error Log Path. However, the API also exposes test_config_cmd, reload_cmd and restart_cmd. While the UI doesn't allow users to modify any of these settings, it is possible to do so by sending a request to the API.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-pxmr-q2x3-9x9m for updates and patch information.
    Vendor References

    CVEs related to QID 996667

    Software Advisories
    Advisory ID Software Component Link
    GHSA-pxmr-q2x3-9x9m github.com/0xJacky/Nginx-UI URL Logo github.com/advisories/GHSA-pxmr-q2x3-9x9m