Executive brief
Nginx-UI, a web-based management interface for Nginx configurations, contains a vulnerability that allows any logged-in user to execute arbitrary system commands. By modifying a hidden configuration setting via the API, an attacker can gain full control over the underlying server with root privileges. This could lead to a complete system takeover, unauthorized data access, or service disruption.
Technical details
Nginx-UI is vulnerable to command injection (CWE-77) due to improper authorization and input validation in its settings API. While the web UI restricts modification of the 'Terminal Start Command' (start_cmd), the backend 'SaveSettings' function in 'api/system/settings.go' allows any authenticated user (regardless of role) to update this value via a POST request to '/api/settings'. This value is subsequently used as an argument for 'exec.Command' in the 'NewPipeLine' function when a user opens a terminal session. An attacker with low-privileged credentials can overwrite this setting with a shell command (e.g., 'bash') and trigger its execution by opening a terminal, resulting in remote code execution as the root user. The issue is fixed in version 1.9.10-0.20231219184941-827e76c46e63.
Affected products
- 0xJacky Nginx-UI < 1.9.10-0.20231219184941-827e76c46e63
Timeline
- 2024-01-11: advisory: GitHub Advisory GHSA-8r25-68wm-jw35 published
- 2024-01-11: disclosed: CVE-2024-22198 assigned