CVE-2024-36991

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/07/2024
Last modified:
15/10/2024

Description

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* 9.0.0 (including) 9.0.10 (excluding)
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* 9.1.0 (including) 9.1.5 (excluding)
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* 9.2.0 (including) 9.2.2 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*