PT-2024-9875 · Splunk · Splunk Cloud Platform+2

Anton

+1

·

Published

2024-12-10

·

Updated

2024-12-10

·

CVE-2024-53243

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Splunk Enterprise versions prior to 9.3.2, 9.2.4, and 9.1.7 Splunk Secure Gateway app on Splunk Cloud Platform versions prior to 3.2.462, 3.7.18, and 3.8.5
Description: The issue is related to improper access control in the Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints. This could allow a low-privileged user without the "admin" or "power" Splunk roles to see alert search query responses. The vulnerability may enable a remote attacker to gain unauthorized access to protected information due to insufficient protection of service data resulting from improper access control to the KV Store.
Recommendations: For Splunk Enterprise versions prior to 9.3.2, 9.2.4, and 9.1.7, update to version 9.3.2, 9.2.4, or 9.1.7 or later. For Splunk Secure Gateway app on Splunk Cloud Platform versions prior to 3.2.462, 3.7.18, and 3.8.5, update to version 3.2.462, 3.7.18, or 3.8.5 or later. As a temporary workaround, consider restricting access to the KV Store collections endpoints until a patch is available.

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-11653
CVE-2024-53243

Affected Products

Splunk Cloud Platform
Splunk Enterprise
Splunk Secure Gateway App