PT-2024-2450 · Splunk · Splunk Enterprise
Alex Napier
·
Published
2024-03-27
·
Updated
2024-04-10
·
CVE-2024-29945
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 9.2.1
Splunk Enterprise versions prior to 9.1.4
Splunk Enterprise versions prior to 9.0.9
Description
The issue is related to the exposure of authentication tokens in Splunk Enterprise. This exposure can occur when the software is run in debug mode or when the JsonWebToken component is configured to log its activity at the DEBUG logging level. A remote attacker could potentially exploit this to elevate their privileges.
Recommendations
For versions prior to 9.2.1, update to version 9.2.1 or later.
For versions prior to 9.1.4, update to version 9.1.4 or later.
For versions prior to 9.0.9, update to version 9.0.9 or later.
As a temporary workaround, consider disabling debug mode and configuring the JsonWebToken component to log at a level other than DEBUG to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise