CVE-2022-31137: Unauthenticated Remote Code Execution in Roxy-WI
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocessexecute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-31137?
CVE-2022-31137 is rated as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-31137?
To fix CVE-2022-31137, upgrade to Roxy-WI version 6.1.1.0 or later.
What can be exploited in CVE-2022-31137?
CVE-2022-31137 can be exploited to run system commands remotely via the subprocess_execute function.
Is my version affected by CVE-2022-31137?
Versions of Roxy-WI prior to 6.1.1.0 are affected by CVE-2022-31137.
What is Roxy-WI related to CVE-2022-31137?
Roxy-WI is a web interface for managing servers like Haproxy, Nginx, Apache, and Keepalived, which is vulnerable in versions before 6.1.1.0.