CVE-2024-45741
Persistent Cross-Site Scripting (XSS) via props.conf on Splunk Enterprise
Severity
Medium 5.4
CVSS 3.1
Exploited
Not listed
EPSS
0.131
96.1th percentile
Discovered by
Not disclosed
Published
Oct 14, 2024
Assigned by splunk
Description
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom configuration file that the "api.uri" parameter from the "/manager/search/apps/local" endpoint in Splunk Web calls. This could result in execution of unauthorized JavaScript code in the browser of a user.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Cloud Platform | SIEM & Log Management | affected-vendor |
| Cisco | Splunk Enterprise | SIEM & Log Management | affected-vendor |
Vendor-reported products (4)
- Splunk · Splunk Enterprise
- Splunk · Splunk Cloud Platform
- splunk · splunk_enterprise
- splunk · splunk_cloud_platform
Credit
Danylo Dmytriiev (DDV_UA)