CVE-2024-39915

Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with network access to inject arbitrary commands via the URL parameter during PDF report generation. The Thruk web application does not properly process the url parameter when generating a PDF report. An authorized attacker with access to the reporting functionality could inject arbitrary commands that would be executed when the script /script/html2pdf.sh is called. The vulnerability can be exploited by an authorized user with network access. This issue has been addressed in version 3.16. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://github.com/sni/Thruk/commit/7e7eb251e76718a07639c4781f0d959d817f173b - () https://github.com/sni/Thruk/commit/7e7eb251e76718a07639c4781f0d959d817f173b -
References () https://github.com/sni/Thruk/security/advisories/GHSA-r7gx-h738-4w6f - () https://github.com/sni/Thruk/security/advisories/GHSA-r7gx-h738-4w6f -

16 Jul 2024, 13:43

Type Values Removed Values Added
Summary
  • (es) Thruk es una interfaz web de monitoreo multibackend para Naemon, Nagios, Icinga y Shinken que utiliza la API Livestatus. Este RCE autenticado en Thruk permite a los usuarios autorizados con acceso a la red inyectar comandos arbitrarios a través del parámetro URL durante la generación de informes PDF. La aplicación web Thruk no procesa correctamente el parámetro de URL al generar un informe en PDF. Un atacante autorizado con acceso a la funcionalidad de informes podría inyectar comandos arbitrarios que se ejecutarían cuando se llame al script /script/html2pdf.sh. La vulnerabilidad puede ser explotada por un usuario autorizado con acceso a la red. Este problema se solucionó en la versión 3.16. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.

15 Jul 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-15 20:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39915

Mitre link : CVE-2024-39915

CVE.ORG link : CVE-2024-39915


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')