PT-2024-9875 · Splunk · Splunk Cloud Platform+2
Anton
+1
·
Published
2024-12-10
·
Updated
2024-12-10
·
CVE-2024-53243
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Splunk Enterprise versions prior to 9.3.2, 9.2.4, and 9.1.7
Splunk Secure Gateway app on Splunk Cloud Platform versions prior to 3.2.462, 3.7.18, and 3.8.5
Description:
The issue is related to improper access control in the Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints. This could allow a low-privileged user without the "admin" or "power" Splunk roles to see alert search query responses. The vulnerability may enable a remote attacker to gain unauthorized access to protected information due to insufficient protection of service data resulting from improper access control to the KV Store.
Recommendations:
For Splunk Enterprise versions prior to 9.3.2, 9.2.4, and 9.1.7, update to version 9.3.2, 9.2.4, or 9.1.7 or later.
For Splunk Secure Gateway app on Splunk Cloud Platform versions prior to 3.2.462, 3.7.18, and 3.8.5, update to version 3.2.462, 3.7.18, or 3.8.5 or later.
As a temporary workaround, consider restricting access to the KV Store collections endpoints until a patch is available.
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Splunk Cloud Platform
Splunk Enterprise
Splunk Secure Gateway App