VYPR
High severity7.0NVD Advisory· Published Jan 11, 2024· Updated Jun 17, 2026

CVE-2024-22196

CVE-2024-22196

Description

Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using DefaultQuery, the "desc" and "id" values are used as default values if the query parameters are not set. Thus, the order and sort_by query parameter are user-controlled and are being appended to the order variable without any sanitization. This issue has been patched in version 2.0.0.beta.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/0xJacky/Nginx-UIGo
< 1.9.10-0.20231219195202-ec93ab05a3ec1.9.10-0.20231219195202-ec93ab05a3ec

Affected products

16
  • 0xJacky/Nginx UI15 versions
    cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*range: <2.0.0
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta4_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta5_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6_patch2:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta8_patch:*:*:*:*:*:*
    • (no CPE)range: < 2.0.0.beta.9
  • ghsa-coords
    Range: < 2.0.0.beta.9

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.