漏洞描述
Roxy-WI是用于管理Haproxy、Nginx和Keepalived服务器的Web界面。CVE-2022-31137 中,攻击者可构造恶意请求,在无需登录的情况下执行任意命令,控制服务器。
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
packetstormsecurity.comhttp://packetstormsecurity.com/files/167805/Roxy-WI-Remote-Command-Execution.html↗packetstormsecurity.comhttp://packetstormsecurity.com/files/171648/Roxy-WI-6.1.0.0-Improper-Authenti...↗packetstormsecurity.comhttp://packetstormsecurity.com/files/171652/Roxy-WI-6.1.1.0-Remote-Code-Execu...↗packetstormsecurity.comhttp://packetstormsecurity.com/files/172547/Roxy-WI-6.1.0.0-Remote-Command-Ex...↗github.comhttps://github.com/hap-wi/roxy-wi/commit/82666df1e60c45dd6aa533b01a392f015d32f755↗github.comhttps://github.com/hap-wi/roxy-wi/security/advisories/GHSA-53r2-mq99-f532↗