Vulnerabilities > CVE-2024-23676 - Unspecified vulnerability in Splunk Cloud and Splunk
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user to exploit.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 12 |