Описание
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enters an infinite loop or an invalid state, rendering the web interface unresponsive. This issue has been patched in version 2.3.4.
Ссылки
- ProductRelease Notes
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.4 (исключая)
cpe:2.3:a:nginxui:nginx_ui:*:*:*:*:*:*:*:*
EPSS
Процентиль: 57%
0.00948
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo
Связанные уязвимости
github
5 месяцев назад
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval
CVSS3: 6.5
fstec
5 месяцев назад
Уязвимость пользовательского интерфейса Nginx UI сервера nginx, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
Процентиль: 57%
0.00948
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20
NVD-CWE-noinfo