CVE-2024-36991
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.130
96.0th percentile
Discovered by
Not disclosed
Published
Jul 1, 2024
Assigned by splunk
Description
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
Weakness: CWE-35
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | affected-vendor |
Vendor-reported products (4)
- Splunk · Splunk Enterprise
- splunk · splunk
- splunk · splunk
- splunk · splunk
Credit
Danylo Dmytriiev (DDV_UA)