{"id":"CVE-2024-23828","aliases":["GHSA-qcjq-7f7v-pvc8","GO-2024-2480"],"url":"https://o3.security/vulnerability/CVE-2024-23828","summary":"Nginx-UI authenticated RCE through injecting into the application config via CRLF","details":"Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been patched in version 2.0.0.beta.12.","published":"2024-01-29T16:49:51.440Z","modified":"2026-07-15T01:49:16.727017356Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/0xJacky/Nginx-UI","fixedVersion":"1.9.10-0.20240126104956-d70e37c8575e"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-qcjq-7f7v-pvc8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23828.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23828"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:16.727017356Z"}}