Vulnerability record · CVE-2023-34096 · published 8 June 2023
CVE-2023-34096: Thruk panorama.pm path traversal allows arbitrary file upload
Thruk · Thruk
Thruk versions 3.06 and prior fail to filter, validate or sanitize the location parameter in panorama.pm, allowing path traversal via dot and slash characters. An authenticated attacker can write files to any directory with write permissions on the host. A fix is available in version 3.06.2.
Description
Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it accepts any kind of characters. For a path traversal attack, the only characters required were the dot (`.`) and the slash (`/`). A fix is available in version 3.06.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity and availability impact, public exploit code available, and very high EPSS probability, though not in KEV.
What it is
Thruk versions 3.06 and prior fail to filter, validate or sanitize the location parameter in panorama.pm, allowing path traversal via dot and slash characters. An authenticated attacker can write files to any directory with write permissions on the host. A fix is available in version 3.06.2.
Impact
An attacker can upload arbitrary files to any writable location on the affected system, which can lead to code execution or system compromise depending on where files are written.
Attack surface
Reachable over the network through the Thruk web interface; the CVSS vector indicates low privileges are required and no user interaction is needed.
Exploitation
Public exploit code and a Metasploit-style module are referenced, and EPSS is 0.62682 (99.155th percentile), but the CVE is not listed in CISA KEV.
What to do
- Upgrade Thruk to version 3.06.2 or later.
- Restrict network access to the Thruk web interface to trusted management networks.
- Enforce least privilege on the Thruk service account so it cannot write outside required directories.
- Audit and remove unnecessary write permissions on directories accessible to the Thruk process.
Detection
- Monitor Thruk access logs for requests to panorama endpoints containing '../' or encoded traversal sequences.
- Alert on file creation or modification events in unexpected directories by the Thruk process user.
- Review web server and application logs for anomalous upload activity from authenticated Thruk users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-34096 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.