7.1

CVE-2024-36989

Low-privileged user could create notifications in Splunk Web Bulletin Messages

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SplunkCloud Version >= 9.1.2312 < 9.1.2312.200
SplunkSplunk SwEditionenterprise Version >= 9.0.0 < 9.0.10
SplunkSplunk SwEditionenterprise Version >= 9.1.0 < 9.1.5
SplunkSplunk SwEditionenterprise Version >= 9.2.0 < 9.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.439
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
prodsec@splunk.com 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.