CVE-2024-23676

In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user to exploit.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

History

29 Jan 2024, 17:57

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:splunk:cloud:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
References () https://advisory.splunk.com/advisories/SVD-2024-0106 - () https://advisory.splunk.com/advisories/SVD-2024-0106 - Vendor Advisory
References () https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd/ - () https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd/ - Vendor Advisory
CVSS v2 : unknown
v3 : 4.6
v2 : unknown
v3 : 3.5
First Time Splunk splunk
Splunk cloud
Splunk

24 Jan 2024, 19:15

Type Values Removed Values Added
References
  • () https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd/ -

23 Jan 2024, 13:44

Type Values Removed Values Added
Summary
  • (es) En las versiones de Splunk inferiores a 9.0.8 y 9.1.3, el comando SPL “mrollup” permite a un usuario con pocos privilegios ver métricas en un índice para el que no tiene permiso. Esta vulnerabilidad requiere la interacción de un usuario con altos privilegios para poder explotarla.

22 Jan 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-22 21:15

Updated : 2024-04-10 01:15


NVD link : CVE-2024-23676

Mitre link : CVE-2024-23676

CVE.ORG link : CVE-2024-23676


JSON object : View

Products Affected

splunk

  • splunk
  • cloud
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation