PT-2024-4749 · Splunk · Splunk Cloud Platform+1
Fredrik Alexandersson
·
Published
2024-05-30
·
Updated
2024-10-15
·
CVE-2024-36997
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Splunk Enterprise versions prior to 9.2.2
Splunk Enterprise versions prior to 9.1.5
Splunk Enterprise versions prior to 9.0.10
Splunk Cloud Platform versions prior to 9.1.2312
Description:
The issue is related to the Splunk Web interface of the Splunk Enterprise platform for operational analysis, which fails to take measures to protect the web page structure. This could potentially allow a remote attacker to perform cross-site scripting (XSS) attacks. An admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the
conf-web/settings REST endpoint, potentially causing a persistent cross-site scripting (XSS) exploit.Recommendations:
For Splunk Enterprise versions prior to 9.2.2, update to version 9.2.2 or later.
For Splunk Enterprise versions prior to 9.1.5, update to version 9.1.5 or later.
For Splunk Enterprise versions prior to 9.0.10, update to version 9.0.10 or later.
For Splunk Cloud Platform versions prior to 9.1.2312, update to version 9.1.2312 or later.
As a temporary workaround, consider restricting access to the
conf-web/settings REST endpoint until a patch is available.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Splunk Cloud Platform
Splunk Enterprise