PT-2024-20104 · Thruk · Thruk
Shapas
·
Published
2024-01-29
·
Updated
2024-02-05
·
CVE-2024-23822
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Thruk versions prior to 3.12
Description
The Thruk web monitoring application has a vulnerability in its file upload form, allowing a threat actor to upload files to any path on the server for which they have permissions. This issue is known as Path Traversal or Directory Traversal.
Recommendations
For versions prior to 3.12, update to version 3.12 to resolve the issue. As a temporary workaround, consider restricting access to the file upload form until the update can be applied.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thruk