Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29945


In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either Splunk Enterprise runs in debug mode or the JsonWebToken component has been configured to log its activity at the DEBUG logging level.


Published

2024-03-27T17:15:54.087

Last Modified

2024-11-21T09:08:40.310

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-532
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application splunk splunk < 9.0.9 Yes
Application splunk splunk < 9.1.4 Yes
Application splunk splunk < 9.2.1 Yes

References