CVE-2024-36991
Severity CVSS v4.0: 
            Pending analysis
                                                    Type: 
          
                          CWE-22
                        Path Traversal
          
        Publication date: 
                          01/07/2024
                  Last modified: 
                          15/10/2024
                  Description
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
              Impact
Base Score 3.x
          7.50
        Severity 3.x
          HIGH
        Vulnerable products and versions
| CPE | From | Up to | 
|---|---|---|
| cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | 9.0.0 (including) | 9.0.10 (excluding) | 
| cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | 9.1.0 (including) | 9.1.5 (excluding) | 
| cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | 9.2.0 (including) | 9.2.2 (excluding) | 
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | 
To consult the complete list of CPE names with products and versions, see this page



