CVE-2024-23678

Deserialization of Untrusted Data on Splunk Enterprise for Windows through Path Traversal from Separate Disk Partition

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.002
12.7th percentile
Discovered by
Not disclosed
Published
Jan 22, 2024
Assigned by splunk

Description

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Cisco Splunk Enterprise SIEM & Log Management affected-vendor
Vendor-reported products (1)
  • Splunk · Splunk Enterprise

Credit

Danylo Dmytriiev (DDV_UA)

Something wrong here?