Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-36983


In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.


Published

2024-07-01T17:15:06.257

Last Modified

2025-03-07T17:13:55.270

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application splunk splunk < 9.0.10 Yes
Application splunk splunk < 9.1.5 Yes
Application splunk splunk < 9.2.2 Yes
Application splunk splunk_cloud_platform < 9.1.2308.207 Yes
Application splunk splunk_cloud_platform < 9.1.2312.109 Yes

References