CVE-2023-34096
Summary
| CVE | CVE-2023-34096 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-08 19:15:00 UTC |
| Updated | 2023-06-19 18:15:00 UTC |
| Description | Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it accepts any kind of characters. For a path traversal attack, the only characters required were the dot (`.`) and the slash (`/`). A fix is available in version 3.06.2. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - galoget/Thruk-CVE-2023-34096: Thruk Monitoring Web Interface <= 3.06 vulnerable to CVE-2023-34096 (Path Traversal). | MISC | github.com | |
| Path Traversal Vulnerability in panorama.pm · Advisory · sni/Thruk · GitHub | MISC | github.com | |
| packetstormsecurity.com/files/172822/Thruk-Monitoring-Web-Interface-3.06-Path-Travers... | MISC | packetstormsecurity.com | |
| Thruk Monitoring Web Interface 3.06 - Path Traversal - Perl webapps Exploit | MISC | www.exploit-db.com | |
| Thruk/panorama.pm at 1bc5a5804bf9fc22e82a4eadb21a1795954f0867 · sni/Thruk · GitHub | MISC | github.com | |
| panorama: fix folder validation · sni/Thruk@cf03f67 · GitHub | MISC | github.com | |
| Thruk/panorama.pm at 1bc5a5804bf9fc22e82a4eadb21a1795954f0867 · sni/Thruk · GitHub | MISC | github.com | |
| CVE-2023-34096: Path Traversal Vulnerability in Thruk Monitoring Web Interface ~ Ethical Hacking, Malware Analysis, Disinfection Techniques and more... | MISC | galogetlatorre.blogspot.com | |
| update changelog · sni/Thruk@26de047 · GitHub | MISC | github.com | |
| Thruk/panorama.pm at 1bc5a5804bf9fc22e82a4eadb21a1795954f0867 · sni/Thruk · GitHub | MISC | github.com | |
| Thruk/panorama.pm at 1bc5a5804bf9fc22e82a4eadb21a1795954f0867 · sni/Thruk · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.