Back to Database
Status published
High
CVE-2024-49368
Unchecked logrotate settings lead to arbitrary command execution
Vulnerability Description
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-49368
Credits & Attribution
No credits recorded in the NVD database.
References
More from 0xJacky
View All →CVE-2024-49367
Nginx UI's log path can be controlled
Medium
5.5
CVE-2024-49366
Nginx UI's json field can construct a directory traversal payload, causing arbitrary files to be written
High
7.7
CVE-2024-23828
Nginx-UI authenticated RCE through injecting into the application config via CRLF
High
8.8
CVE-2024-23827
Nginx-UI arbitrary file write through the Import Certificate feature
Critical
9.8
CVE-2024-22198
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
High
7.1
Affected Vendor
0xJacky
View all reports →Affected Software
nginx-ui
Vulnerable Versions:
< 2.0.0-beta.36
Timeline
Official Publish:
October 21st, 2024
Last Modified:
November 1st, 2024
Added to House:
July 22nd, 2026