In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.
References
Link | Resource |
---|---|
https://advisory.splunk.com/advisories/SVD-2024-0302 | Vendor Advisory |
https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-03-27 17:15
Updated : 2024-04-10 01:15
NVD link : CVE-2024-29946
Mitre link : CVE-2024-29946
CVE.ORG link : CVE-2024-29946
JSON object : View
Products Affected
splunk
- splunk