CVE-2024-36989
Severity CVSS v4.0: 
            Pending analysis
                                                    Type: 
          
                        Unavailable / Other
          
        Publication date: 
                          01/07/2024
                  Last modified: 
                          10/10/2024
                  Description
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.
              Impact
Base Score 3.x
          4.30
        Severity 3.x
          MEDIUM
        Vulnerable products and versions
| CPE | From | Up to | 
|---|---|---|
| cpe:2.3:a:splunk:cloud:*:*:*:*:*:*:*:* | 9.1.2312 (including) | 9.1.2312.200 (excluding) | 
| cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | 9.0.0 (including) | 9.0.10 (excluding) | 
| cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | 9.1.0 (including) | 9.1.5 (excluding) | 
| cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | 9.2.0 (including) | 9.2.2 (excluding) | 
To consult the complete list of CPE names with products and versions, see this page



