Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kof2002

#48458of 53,622
5.3Total CVSS
Vulnerabilities · 1
PT-2018-10552
5.3
2018-06-08
Splunk · Splunk · CVE-2018-11409
**Name of the Vulnerable Software and Affected Versions** Splunk versions prior to 7.0.1 **Description** The issue allows information disclosure by appending "/api/v1/server/info/server-info?output mode=json" to a query. This can be used to discover sensitive information, such as a license key. **Recommendations** For versions prior to 7.0.1, consider restricting access to the "/api/v1/server/info/server-info" endpoint to minimize the risk of exploitation. Avoid using the `output mode` parameter with the value `json` in the affected API endpoint until the issue is resolved.