Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | nginx-ui δÊÚȨ±¸·ÝÏÂÔØÓë¼ÓÃÜÃÜԿй¶Îó²î |
CVE ID | CVE-2026-27944 |
Îó²îÀàÐÍ | δÊÚȨ»á¼û | ·¢Ã÷ʱ¼ä | 2026-3-9 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
nginx-uiÊÇÒ»¿îÓÃÓÚÖÎÀíNginxµÄ¿ªÔ´Web¿ÉÊÓ»¯ÖÎÀí¹¤¾ß£¬£¬£¬Ìṩ»ùÓÚä¯ÀÀÆ÷µÄͼÐλ¯½çÃæ£¬£¬£¬ÓÃÓÚÉèÖúÍά»¤NginxЧÀÍÆ÷¡£¡£¡£¸ÃÏîĿ֧³ÖÕ¾µãÉèÖÃÖÎÀí¡¢Ö¤ÊéÖÎÀí¡¢ÈÕÖ¾Éó²é¡¢ÉèÖÃÎļþ±à¼¼°ÔÚÏßÖØÔØµÈ¹¦Ð§£¬£¬£¬Ö¼ÔÚ¼ò»¯NginxµÄÔËάºÍÖÎÀíÁ÷³Ì¡£¡£¡£nginx-uiͨ³£°²ÅÅÔÚЧÀÍÆ÷ÉÏ£¬£¬£¬Í¨¹ýWeb¿ØÖÆÌ¨ÊµÏÖ¶ÔNginxÉèÖúÍÔËÐÐ״̬µÄ¼¯ÖÐÖÎÀí¡£¡£¡£
2026Äê3ÔÂ9ÈÕ£¬£¬£¬°ÙÀÖ²©Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½nginx-uiδÊÚȨ±¸·ÝÏÂÔØÓë¼ÓÃÜÃÜԿй¶Îó²î¡£¡£¡£ÓÉÓÚ/api/backup½Ó¿ÚδÉèÖÃÉí·ÝÈÏÖ¤»úÖÆ£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÔÚÎÞÐèµÇ¼µÄÇéÐÎÏÂÖ±½Ó»á¼û¸Ã½Ó¿Ú²¢ÏÂÔØÏµÍ³ÍêÕû±¸·ÝÎļþ¡£¡£¡£Í¬Ê±£¬£¬£¬Ð§ÀÍÆ÷ÔÚÏìӦͷX-Backup-SecurityÖÐÒÔÃ÷ÎÄÐÎʽ·µ»ØÓÃÓÚ½âÃܱ¸·ÝµÄAES-256¼ÓÃÜÃÜÔ¿ºÍIV£¬£¬£¬µ¼Ö±¸·ÝÊý¾ÝµÄ¼ÓÃܱ£»£»£»£»¤Ê§Ð§¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÃÜÔ¿¶ÔÏÂÔØµÄ±¸·ÝÎļþ¾ÙÐнâÃÜ£¬£¬£¬´Ó¶ø»ñÈ¡Êý¾Ý¿âÐÅÏ¢¡¢Óû§Æ¾Ö¤¡¢»á»°ÁîÅÆ¡¢NginxÉèÖÃÎļþÒÔ¼°SSL˽ԿµÈÃô¸ÐÊý¾Ý£¬£¬£¬Ôì³ÉÑÏÖØÐÅϢй¶Σº¦£¬£¬£¬²¢¿ÉÄܽøÒ»²½Òý·¢ÕË»§½ÓÊÜ¡¢Ð§ÀÍαÔì»òϵͳÉèÖñ»ÀÄÓõÈÇå¾²Ó°Ïì¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
nginx-ui < 2.3.2
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/0xJacky/nginx-ui/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762/https://nvd.nist.gov/vuln/detail/CVE-2026-27944