CVE-2024-22164

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:splunk:enterprise_security:*:*:*:*:*:*:*:*

History

16 Jan 2024, 17:40

Type Values Removed Values Added
References () https://advisory.splunk.com/advisories/SVD-2024-0101 - () https://advisory.splunk.com/advisories/SVD-2024-0101 - Vendor Advisory
References () https://research.splunk.com/application/bb85b25e-2d6b-4e39-bd27-50db42edcb8f/ - () https://research.splunk.com/application/bb85b25e-2d6b-4e39-bd27-50db42edcb8f/ - Vendor Advisory
First Time Splunk enterprise Security
Splunk
CPE cpe:2.3:a:splunk:enterprise_security:*:*:*:*:*:*:*:*
CWE CWE-770

10 Jan 2024, 22:15

Type Values Removed Values Added
References
  • () https://research.splunk.com/application/bb85b25e-2d6b-4e39-bd27-50db42edcb8f/ -
Summary
  • (es) En las versiones de Splunk Enterprise Security (ES) inferiores a 7.1.2, un atacante puede utilizar archivos adjuntos de investigación para realizar una denegación de servicio (DoS) a la investigación. El endpoint del archivo adjunto no limita adecuadamente el tamaño de la solicitud, lo que permite que un atacante haga que la investigación se vuelva inaccesible.

09 Jan 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 17:15

Updated : 2024-04-10 01:15


NVD link : CVE-2024-22164

Mitre link : CVE-2024-22164

CVE.ORG link : CVE-2024-22164


JSON object : View

Products Affected

splunk

  • enterprise_security
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-400

Uncontrolled Resource Consumption