PT-2024-7164 · Splunk · Splunk Enterprise

Eric Mcginnis

+1

·

Published

2024-10-14

·

Updated

2024-10-17

·

CVE-2024-45738

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 9.3.1 Splunk Enterprise versions prior to 9.2.3 Splunk Enterprise versions prior to 9.1.6
Description The software potentially exposes sensitive HTTP parameters to the internal index if the REST Calls log channel is configured at the DEBUG logging level. This issue is related to insufficient protection of service data, which could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 9.3.1, update to version 9.3.1 or later to resolve the issue. For versions prior to 9.2.3, update to version 9.2.3 or later to resolve the issue. For versions prior to 9.1.6, update to version 9.1.6 or later to resolve the issue. As a temporary workaround, consider configuring the REST Calls log channel at a logging level other than DEBUG to minimize the risk of sensitive HTTP parameter exposure.

Fix

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-08501
CVE-2024-45738

Affected Products

Splunk Enterprise