VYPR
High severity8.8NVD Advisory· Published Jan 29, 2024· Updated Jun 17, 2026

CVE-2024-23828

CVE-2024-23828

Description

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been patched in version 2.0.0.beta.12.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/0xJacky/Nginx-UIGo
< 1.9.10-0.20240126104956-d70e37c8575e1.9.10-0.20240126104956-d70e37c8575e

Affected products

20
  • 0xJacky/Nginx UI19 versions
    cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*+ 18 more
    • cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*range: <2.0.0
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta10:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta10_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta11:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta4_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta5_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6_patch2:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta6_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta8_patch:*:*:*:*:*:*
    • cpe:2.3:a:nginxui:nginx_ui:2.0.0:beta9:*:*:*:*:*:*
    • (no CPE)range: < v2.0.0.beta.12
  • ghsa-coords
    Range: < 2.0.0-beta.12

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.