In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-07-01 17:15
Updated : 2024-07-02 12:09
NVD link : CVE-2024-36989
Mitre link : CVE-2024-36989
CVE.ORG link : CVE-2024-36989
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control