6.5

CVE-2024-45732

Low-privileged user could run search as nobody in SplunkDeploymentServerConfig app

In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the "nobody" Splunk user in the SplunkDeploymentServerConfig app. This could let the low-privileged user access potentially restricted data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Splunk ≫ Splunk SwEdition enterprise Version >= 9.2.0 < 9.2.3
Splunk ≫ Splunk Version 9.3.0 SwEdition enterprise
Splunk ≫ Splunk Cloud Platform Version < 9.1.2308.208
Splunk ≫ Splunk Cloud Platform Version >= 9.1.2312.100 < 9.1.2312.110
Splunk ≫ Splunk Cloud Platform Version >= 9.2.2403.102 < 9.2.2403.103
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.312
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
prodsec@splunk.com 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://advisory.splunk.com/advisories/SVD-2024-1002
Vendor Advisory
https://research.splunk.com/application/f765c3fe-c3b6-4afe-a932-11dd4f3a024f/
Vendor Advisory