In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
2024-07-01T17:15:07.860
2024-11-21T09:22:59.347
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | splunk | splunk | < 9.0.10 | Yes |
Application | splunk | splunk | < 9.1.5 | Yes |
Application | splunk | splunk | < 9.2.2 | Yes |
Operating System | microsoft | windows | - | No |