CVE-2022-31125
Roxy-WI vulnerability analysis and mitigation

Overview

Roxy-wi, an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers, was found to contain a critical authentication bypass vulnerability (CVE-2022-31125). The vulnerability affects versions before 6.1.1.0 and allows remote, unauthenticated attackers to bypass authentication and access admin functionality by sending specially crafted HTTP requests (GitHub Advisory).

Technical details

The vulnerability received a CVSS v3.1 base score of 10.0 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L). The vulnerability is classified as CWE-287 (Improper Authentication) and allows attackers to bypass authentication controls through specially crafted HTTP requests. The attack vector is network-based, requires low complexity, needs no privileges or user interaction, and has a changed scope with high impact on confidentiality and integrity (NVD, GitHub Advisory).

Impact

The vulnerability allows unauthorized access to admin functionality, potentially leading to complete system compromise. The CVSS metrics indicate high impact on both confidentiality and integrity of the system, with a lower impact on availability. This means attackers could access and modify sensitive administrative data without authentication (GitHub Advisory).

Mitigation and workarounds

Users are advised to upgrade to version 6.1.1.0 or later which contains a patch for this vulnerability. There are no known workarounds for this issue (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Roxy-WI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-43804HIGH8.8
  • Roxy-WIRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoNoAug 29, 2024
CVE-2023-25803HIGH7.5
  • Roxy-WIRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesMar 13, 2023
CVE-2023-25802HIGH7.5
  • Roxy-WIRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesMar 13, 2023
CVE-2023-29004MEDIUM6.5
  • Roxy-WIRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoNoApr 17, 2023
CVE-2023-25804MEDIUM5.3
  • Roxy-WIRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesMar 15, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management