PT-2024-35690 · Splunk · Splunk Cloud Platform+1

Published

2024-12-10

·

Updated

2024-12-10

·

CVE-2024-53245

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 9.3.0 Splunk Enterprise versions prior to 9.2.4 Splunk Enterprise versions prior to 9.1.7 Splunk Cloud Platform versions prior to 9.1.2312.206
Description A low-privileged user without the "admin" or "power" Splunk roles, but with a username matching a role that has read access to dashboards, could potentially see the dashboard name and the dashboard XML by cloning the dashboard.
Recommendations For Splunk Enterprise versions prior to 9.3.0, update to version 9.3.0 or later. For Splunk Enterprise versions prior to 9.2.4, update to version 9.2.4 or later. For Splunk Enterprise versions prior to 9.1.7, update to version 9.1.7 or later. For Splunk Cloud Platform versions prior to 9.1.2312.206, update to version 9.1.2312.206 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-53245

Affected Products

Splunk Cloud Platform
Splunk Enterprise