PT-2024-20104 · Thruk · Thruk

Shapas

·

Published

2024-01-29

·

Updated

2024-02-05

·

CVE-2024-23822

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Thruk versions prior to 3.12
Description The Thruk web monitoring application has a vulnerability in its file upload form, allowing a threat actor to upload files to any path on the server for which they have permissions. This issue is known as Path Traversal or Directory Traversal.
Recommendations For versions prior to 3.12, update to version 3.12 to resolve the issue. As a temporary workaround, consider restricting access to the file upload form until the update can be applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-23822
GHSA-4MRH-MX7X-RQJX

Affected Products

Thruk