CVE-2024-36991

Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.130
96.0th percentile
Discovered by
Not disclosed
Published
Jul 1, 2024
Assigned by splunk

Description

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

Weakness: CWE-35

Affected products

Vendor Product Category Matched by
Cisco Splunk Enterprise SIEM & Log Management affected-vendor
Vendor-reported products (4)
  • Splunk · Splunk Enterprise
  • splunk · splunk
  • splunk · splunk
  • splunk · splunk

Credit

Danylo Dmytriiev (DDV_UA)

Something wrong here?