Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form that allows a threat actor to arbitrarily upload files to the server to any path they desire and have permissions for. This vulnerability is known as Path Traversal or Directory Traversal. Version 3.12 fixes the issue.
References
Link | Resource |
---|---|
https://github.com/sni/Thruk/commit/1aa9597cdf2722a69651124f68cbb449be12cc39 | Patch |
https://github.com/sni/Thruk/security/advisories/GHSA-4mrh-mx7x-rqjx | Exploit Patch Vendor Advisory |
https://github.com/sni/Thruk/commit/1aa9597cdf2722a69651124f68cbb449be12cc39 | Patch |
https://github.com/sni/Thruk/security/advisories/GHSA-4mrh-mx7x-rqjx | Exploit Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 08:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/sni/Thruk/commit/1aa9597cdf2722a69651124f68cbb449be12cc39 - Patch | |
References | () https://github.com/sni/Thruk/security/advisories/GHSA-4mrh-mx7x-rqjx - Exploit, Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
05 Feb 2024, 18:04
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
First Time |
Thruk
Thruk thruk |
|
CPE | cpe:2.3:a:thruk:thruk:*:*:*:*:*:*:*:* | |
References | () https://github.com/sni/Thruk/commit/1aa9597cdf2722a69651124f68cbb449be12cc39 - Patch | |
References | () https://github.com/sni/Thruk/security/advisories/GHSA-4mrh-mx7x-rqjx - Exploit, Patch, Vendor Advisory |
29 Jan 2024, 16:19
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-29 16:15
Updated : 2024-11-21 08:58
NVD link : CVE-2024-23822
Mitre link : CVE-2024-23822
CVE.ORG link : CVE-2024-23822
JSON object : View
Products Affected
thruk
- thruk
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')