CVE-2024-49367: Nginx UI's log path can be controlled
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at /api/configs to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49367?
CVE-2024-49367 has a critical severity rating due to its ability to allow unauthorized access to sensitive files on the server.
How do I fix CVE-2024-49367?
To fix CVE-2024-49367, upgrade to Nginx UI version 2.0.0-beta.36 or later.
What are the affected versions for CVE-2024-49367?
CVE-2024-49367 affects Nginx UI versions prior to 2.0.0-beta.36.
What is the impact of CVE-2024-49367?
CVE-2024-49367 allows attackers to control the log path and read directories and file contents on the server.
Who is affected by CVE-2024-49367?
Organizations using Nginx UI versions before 2.0.0-beta.36 are at risk from CVE-2024-49367.