CVE-2024-45734

In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboards. The images on the machine could be exposed by exporting the dashboard as a PDF, using the local image path in the img tag in the source extensible markup language (XML) code for the Splunk classic dashboard.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

History

16 Oct 2024, 22:20

Type Values Removed Values Added
References () https://advisory.splunk.com/advisories/SVD-2024-1004 - () https://advisory.splunk.com/advisories/SVD-2024-1004 - Vendor Advisory
References () https://research.splunk.com/application/7464e2dc-98a5-4af9-87a1-fa6d5a256fa6/ - () https://research.splunk.com/application/7464e2dc-98a5-4af9-87a1-fa6d5a256fa6/ - Vendor Advisory
First Time Splunk splunk
Splunk
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

15 Oct 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) En las versiones 9.3.0, 9.2.3 y 9.1.6 de Splunk Enterprise, un usuario con pocos privilegios que no tenga los roles de "administrador" o "poder" de Splunk podría ver imágenes en la máquina que ejecuta Splunk Enterprise mediante la función de exportación a PDF en los paneles clásicos de Splunk. Las imágenes en la máquina podrían exponerse exportando el panel como PDF, utilizando la ruta de la imagen local en la etiqueta img en el código fuente del lenguaje de marcado extensible (XML) para el panel clásico de Splunk.

14 Oct 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-14 17:15

Updated : 2024-10-16 22:20


NVD link : CVE-2024-45734

Mitre link : CVE-2024-45734

CVE.ORG link : CVE-2024-45734


JSON object : View

Products Affected

splunk

  • splunk
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control