Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23675


In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.


Published

2024-01-22T21:15:10.263

Last Modified

2024-11-21T08:58:08.930

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application splunk cloud < 9.1.2312.100 Yes
Application splunk splunk < 9.0.8 Yes
Application splunk splunk < 9.1.3 Yes

References