CVE-2024-22196 Information
Jan 12, 2024
cve
Description
Nginx-UI is an online statistics for Server Indicators?? Monitor CPU usage memory usage load average and disk usage in real-time. This issue may lead to information disclosure. By using DefaultQuery the \desc\ and \id\ values are used as default values if the query parameters are not set. Thus the order and sort_by query parameter are user-controlled and are being appended to the order variable without any sanitization. This issue has been patched in version 2.0.0.beta.9.
Reference
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h374-mm57-879c https://github.com/0xJacky/nginx-ui/commit/ec93ab05a3ecbb6bcf464d9dca48d74452df8a5b
Share on: