mirror of
https://github.com/NginxProxyManager/nginx-proxy-manager.git
synced 2026-04-26 18:05:54 +03:00
[GH-ISSUE #515] Shellscript upload possible via upload of 404 pages #437
Labels
No labels
awaiting feedback
bug
cannot reproduce
dns provider request
duplicate
enhancement
enhancement
enhancement
good first issue
help wanted
invalid
need more info
no certbot plugin available
product-support
pull-request
question
stale
troll
upstream issue
v2
v2
v2
v3
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/nginx-proxy-manager-NginxProxyManager#437
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @DragonicDefson on GitHub (Jul 20, 2020).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/515
What happened
Bug Description
Behaviour
Operating System
@netstx commented on GitHub (Aug 1, 2020):
@DragonicDefson do you have any more details on this, like logs or anything else you could share? To me this sounds like a pretty serious bug that we should look into.
@jc21 do you have any feedback on this issue?
@DragonicDefson commented on GitHub (Aug 1, 2020):
@raffieyeah I don't have any more details or logs, because i had root login enabled (no other accounts) so they disabled SSH as well for my IP, had to reset the server which as well took away all logs, but i'm really sure it was a shell script.
An way to protect for this is parsing the inserted code the right way before using it as a 404 page.
If it happens again i will report back to you guys.
also, i'm modifying the proxy manager with custom logo's for my company. i don't know if i'm allowed to do this
but i wanted you guys to know this.
@chaptergy commented on GitHub (May 12, 2021):
The only upload there is, is the certificate upload, and generally everything (even the api) is only available for logged in users. If you could upload 404 pages back then, it seems like this was removed, so this issue is no longer relevant. And if the underlying OS was affected, this sounds like an issue with docker, as it is responsible for the isolation.