Description
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches.
Problem types
CWE-287: Improper Authentication
CWE-306: Missing Authentication for Critical Function
Product status
References
github.com/...oxy-wi/security/advisories/GHSA-4fcm-qgg8-w2vf
github.com/...oxy-wi/security/advisories/GHSA-4fcm-qgg8-w2vf