CVE-2024-23678
Deserialization of Untrusted Data on Splunk Enterprise for Windows through Path Traversal from Separate Disk Partition
Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.002
12.7th percentile
Discovered by
Not disclosed
Published
Jan 22, 2024
Assigned by splunk
Description
In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.
Weakness: CWE-20
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | affected-vendor |
Vendor-reported products (1)
- Splunk · Splunk Enterprise
Credit
Danylo Dmytriiev (DDV_UA)