Can no longer save bookmarks in thruk #1383
Replies: 4 comments 4 replies
-
Hello I got the same problem and this is linked to the last version of apache2 and UnsafeAllow3F. This should be linked to this : https://www.cve.org/CVERecord?id=CVE-2024-38474
|
Beta Was this translation helpful? Give feedback.
-
I change the bookmarks form tag to POST method which prevents the %3f issue, because the relevant data os now post data. Let me know if there are more things not working with that apache version. |
Beta Was this translation helpful? Give feedback.
-
yes, the fix is to use POST a form: 825dd5b |
Beta Was this translation helpful? Give feedback.
-
Thank you for the quick solution. I'm going to take the new files in the nightly builds and test it on my prod (with backup of course) |
Beta Was this translation helpful? Give feedback.
-
The thruk web interface will not allow me to save new bookmarks. I can get as far as entering the name of the new bookmark in the "Name" field, but when I click the "Add Bookmark" button, I get an error page saying
Here are the thruk.log and the apache.log, which I have extracted just the portions written during typical attempts to create a new bookmark. They are anonymized to the best of my ability.
thruk.log
apache.log
I have 2 omd sites set up on separate systems, one of which I use for testing purposes only. I can reproduce this problem on both sites.
The test system has been upgraded to omd 5.40; the other is still at omd 5.30. Both systems are devuan daedalus (debian bookworm), with all of the latest patches and updates from the devuan repos.
The "mysite" user is able to edit the /omd/sites/mysite/var/thruk/users/omdadmin file manually and the changes do show up in the thruk GUI. All files and directories under /omd/sites/mysite are owned by user "mysite."
Until just recently, I did not have a problem creating or modifying bookmarks, although I think it has been a few weeks since the last time I actually did so. But as of a few days ago, this error keeps popping up whenever I try to create a bookmark.
Other than manually modifying the omdadmin file to add a new bookmark, I avoid modifying files under the control of thruk or naemon.
Beta Was this translation helpful? Give feedback.
All reactions