Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-86470DAF8E394E6A6F1ABA3894A5BA87
HistoryJan 29, 2024 - 12:00 a.m.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

2024-01-2900:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
8
nginx-ui
arbitrary write
remote code execution
certification key
path traversal
vulnerability
app.ini
version 2.0.0.beta.12
nginx configurations

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

Low

EPSS

0.002

Percentile

53.3%

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It’s possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.

Affected configurations

Vulners
Node
gonginx-uiRange<v2.0.0-beta.12
VendorProductVersionCPE
gonginx-ui*cpe:2.3:a:go:nginx-ui:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

Low

EPSS

0.002

Percentile

53.3%

Related for GITLAB-86470DAF8E394E6A6F1ABA3894A5BA87