PT-2024-28729 · Thruk · Thruk

Sergey Bobrov

·

Published

2024-07-15

·

Updated

2024-08-13

·

CVE-2024-39915

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thruk versions prior to 3.16
Description This issue allows authorized users with network access to inject arbitrary commands via the URL parameter during PDF report generation. The Thruk web application does not properly process the url parameter when generating a PDF report. An authorized attacker with access to the reporting functionality could inject arbitrary commands that would be executed when the script /script/html2pdf.sh is called. The vulnerability can be exploited by an authorized user with network access.
Recommendations For versions prior to 3.16, upgrade to version 3.16 to address the issue. As a temporary workaround, consider restricting access to the reporting functionality to minimize the risk of exploitation. Avoid using the vulnerable URL parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-39915
GHSA-R7GX-H738-4W6F

Affected Products

Thruk