PT-2022-17651 · Splunk · Splunk Enterprise
Dipak Prajapati
+1
·
Published
2022-05-06
·
Updated
2022-05-17
·
CVE-2022-26070
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 8.1.0
Description
The application leaks the internal error message in the response when handling a mismatched pre-authentication cookie, which contains the Splunk Enterprise local system path.
Recommendations
For versions prior to 8.1.0, update to version 8.1.0 or later to resolve the issue.
Fix
Generation of Error Message Containing Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Splunk Enterprise