Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2024-39915 โ€” AI Deep Analysis Summary

CVSS 10.0 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: Thruk < 3.16 has an **OS Command Injection** flaw. ๐Ÿ“„ When generating PDF reports, it mishandles URL parameters.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: **CWE-94** (Code Injection). ๐Ÿ› The flaw lies in improper handling of URL inputs during PDF generation. ๐Ÿ“ The vulnerable script is `/script/html2pdf.sh`. It fails to sanitize inputs before execution.

Q3Who is affected? (Versions/Components)

๐Ÿข **Affected**: **Thruk** by developer **Sven Nierlein** (sni). ๐Ÿ“‰ **Versions**: All versions **prior to 3.16**. ๐ŸŒ It is an open-source multi-backend monitoring web interface.

Q4What can hackers do? (Privileges/Data)

๐Ÿ’€ **Attacker Actions**: Authorized users can inject **arbitrary commands**. ๐Ÿ–ฅ๏ธ These execute via `/script/html2pdf.sh`. ๐Ÿ”“ **Impact**: High severity (CVSS 9.8).โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”‘ **Threshold**: **Medium**. ๐Ÿ›‘ Requires **Authentication** (PR:L). โš ๏ธ You must have **report generation access**. ๐ŸŒ Attack vector is **Network** (AV:N) with **Low Complexity** (AC:L). No user interaction needed (UI:N).

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿšซ **Public Exp**: **None listed** in current data. ๐Ÿ“‚ `pocs` array is empty. ๐Ÿ” However, the GitHub Advisory and Commit links are provided for verification. ๐Ÿ•ต๏ธโ€โ™‚๏ธ Wild exploitation is not yet confirmed public.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: 1. Check Thruk version (< 3.16). ๐Ÿ“„ 2. Look for `/script/html2pdf.sh` script. ๐ŸŒ 3. Test PDF report generation with malicious URL payloads. ๐Ÿ“ก Use scanners targeting CWE-94 in Thruk modules.

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed**: **Yes**. ๐Ÿ“… Published: 2024-07-15. ๐Ÿ› ๏ธ **Patch**: Upgrade to **Thruk 3.16** or later. ๐Ÿ”— Reference: GitHub Security Advisory (GHSA-r7gx-h738-4w6f) and Commit 7e7eb25.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch Workaround**: 1. **Restrict Access**: Limit report generation permissions to trusted admins only. ๐Ÿ”’ 2. **Network Segmentation**: Isolate the monitoring server. ๐Ÿšซ 3.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: **CRITICAL**. ๐Ÿ“ˆ CVSS Score: **9.8** (High). ๐Ÿšจ Remote Code Execution (RCE) is possible. โณ Patch immediately to prevent server takeover. Do not ignore this!