VYPR
Medium severity6.5NVD Advisory· Published Jun 8, 2023· Updated Jun 17, 2026

CVE-2023-34096

CVE-2023-34096

Description

Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file panorama.pm is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it accepts any kind of characters. For a path traversal attack, the only characters required were the dot (.) and the slash (/). A fix is available in version 3.06.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Thruk/Thruk2 versions
    cpe:2.3:a:thruk:thruk:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:thruk:thruk:*:*:*:*:*:*:*:*range: <3.06.2
    • (no CPE)range: <=3.06
  • Sni/Thrukcpe-rescue
    Range: < 3.06.2

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.