Junglewise Threat Intelligence

CVE-2024-22198: 0xJacky Nginx-UI command injection via start_cmd setting

CVE-2024-22198 · Severity: high · CVSS 7.1 · Published 2024-01-11

Technologies: 0xJacky Nginx-UI, github.com/0xJacky/Nginx-UI (Go). Vendors: 0xJacky, Go.

Executive brief

Nginx-UI, a web-based management interface for Nginx configurations, contains a vulnerability that allows any logged-in user to execute arbitrary system commands. By modifying a hidden configuration setting via the API, an attacker can gain full control over the underlying server with root privileges. This could lead to a complete system takeover, unauthorized data access, or service disruption.

Technical details

Nginx-UI is vulnerable to command injection (CWE-77) due to improper authorization and input validation in its settings API. While the web UI restricts modification of the 'Terminal Start Command' (start_cmd), the backend 'SaveSettings' function in 'api/system/settings.go' allows any authenticated user (regardless of role) to update this value via a POST request to '/api/settings'. This value is subsequently used as an argument for 'exec.Command' in the 'NewPipeLine' function when a user opens a terminal session. An attacker with low-privileged credentials can overwrite this setting with a shell command (e.g., 'bash') and trigger its execution by opening a terminal, resulting in remote code execution as the root user. The issue is fixed in version 1.9.10-0.20231219184941-827e76c46e63.

Affected products

  • 0xJacky Nginx-UI < 1.9.10-0.20231219184941-827e76c46e63

Timeline

  • 2024-01-11: advisory: GitHub Advisory GHSA-8r25-68wm-jw35 published
  • 2024-01-11: disclosed: CVE-2024-22198 assigned

References

Related threats