thruk CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

thruk vulnerability overview

Aggregates CVE and security vulnerability intelligence across all thruk-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk path handling, with potential vendor impact session compromise and vendor impact file overwrite across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-23822 Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form that allows a threat actor to arbitrarily upload files to the server to any path they desire and have permissions for. This vulnerability is known as Path Traversal or Directory Traversal. Version 3.12 fixes the issue. [email protected] 5.4 0.30% 2024-01-29 2024-11-21
CVE-2023-34096 Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it accepts any kind of characters. For a path traversal attack, the only characters required were the dot [email protected] 6.5 45.11% 2023-06-08 2024-11-21
CVE-2021-35490 Thruk before 2.44 allows XSS for a quick command. [email protected] 5.4 0.30% 2021-12-15 2024-11-21
CVE-2021-35489 Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it. [email protected] 6.1 0.40% 2021-11-09 2024-11-21
CVE-2021-35488 Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it. [email protected] 6.1 12.80% 2021-11-09 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence