PT-2024-1240 · Splunk · Splunk Enterprise

Vikram Ashtaputre

·

Published

2024-01-22

·

Updated

2024-04-10

·

CVE-2024-23677

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 9.0.8
Description The issue is related to the Splunk RapidDiag utility, which discloses server responses from external applications in a log file due to insufficient protection of registration data. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 9.0.8, update to version 9.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the log files generated by the Splunk RapidDiag utility to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-00633
CVE-2024-23677

Affected Products

Splunk Enterprise