CVE-2024-39935
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- jc21/nginx proxy manager
- Source
- cve@mitre.org
References
- https://github.com/NginxProxyManager/nginx-proxy-manager/commit/99cce7e2b0da2978411cedd7cac5fffbe15bc46Patch
- https://github.com/NginxProxyManager/nginx-proxy-manager/compare/v2.11.2...v2.11.3Release Notes
- https://github.com/NginxProxyManager/nginx-proxy-manager/issues/3662Issue Tracking
- https://github.com/NginxProxyManager/nginx-proxy-manager/commit/99cce7e2b0da2978411cedd7cac5fffbe15bc46Patch
- https://github.com/NginxProxyManager/nginx-proxy-manager/compare/v2.11.2...v2.11.3Release Notes
- https://github.com/NginxProxyManager/nginx-proxy-manager/issues/3662Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.