Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25804

March 15, 2023, 6:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the `/tmp` folder using a payload `../../../../../tmp/test111_dev`. This issue has been fixed in version 6.3.5.0.

cve

Splunk Engineer - Mid-Atlantic Region (Remote)

@ GuidePoint Security LLC | Remote in NC, VA, WV, MD, DC, DE, NJ, or PA

Security Compliance Analyst

@ Bandwidth | Raleigh, NC

Senior Cybersecurity Specialist - Naval Surface Warfare Center

@ Barbaricum | Crane, Indiana

Blockchain Security Researcher - Australia East

@ OpenZeppelin | Remote - Sydney

Software Engineer (Forensics Product)

@ Sysdig, Inc. | Italy (flexible)

GRC Specialist

@ Inbox Business Technologies | Islamabad, Islamabad Capital Territory, Pakistan

Cyber Security Architect

@ Supernova Technology | Chicago, Illinois

Senior Security Architect - Mid-Atlantic Region (Remote)

@ GuidePoint Security LLC | Remote in NC, VA, MD, DC, DE, NJ, or PA

Senior Cyber Threat Analyst

@ Nozomi Networks | United States, Houston, Texas

IT Security Operations Manager

@ Seldon | London, Hybrid

Cyber Risk Analyst (TS/SCI)

@ Red Gate Group | Reston, VA, United States

Director Product Security

@ Palo Alto Networks | Santa Clara, CA, United States