Thruk is a monitoring and alerting platform with a narrow but strategically positioned footprint in infrastructure oversight systems. Its observed vulnerability surface centers on application-layer input-handling weaknesses, recurrently manifesting as cross-site scripting and path-traversal flaws that reflect the web-interface and file-access demands of a monitoring dashboard.
The number and severity of CVEs published that impact products developed by Thruk over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34096HIGH Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulne | Jun 8, 2023 | 8.8 | 72 | NO | YES |
CVE-2021-35488MEDIUM Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status | Nov 9, 2021 | 6.1 | 31 | NO | YES |
CVE-2024-23822CRITICAL Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form that allows a threat actor to a | Jan 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2021-35489MEDIUM Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could in | Nov 9, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-35490MEDIUM Thruk before 2.44 allows XSS for a quick command. | Dec 15, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thruk.
Media articles that mention a CVE ID that affects a product developed by Thruk — matched by CVE ID, not by vendor name.