Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
References
Link | Resource |
---|---|
https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-hr76-3hxp-5mm3 | Third Party Advisory |
Configurations
Information
Published : 2022-07-06 11:15
Updated : 2022-07-14 07:26
NVD link : CVE-2022-31125
Mitre link : CVE-2022-31125
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
roxy-wi
- roxy-wi