Vulnerabilities > Splunk > Splunk Cloud Platform > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-10 CVE-2024-53246 Cleartext Transmission of Sensitive Information vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information.
network
low complexity
splunk CWE-319
7.5
2024-07-01 CVE-2024-36983 Command Injection vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function.
network
low complexity
splunk CWE-77
8.8
2024-07-01 CVE-2024-36997 Cross-site Scripting vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint.
network
low complexity
splunk CWE-79
8.1
2023-08-30 CVE-2023-40593 Unspecified vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.
network
low complexity
splunk
7.5
2023-08-30 CVE-2023-40594 Unspecified vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.
network
low complexity
splunk
7.5
2023-08-30 CVE-2023-40595 Deserialization of Untrusted Data vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data.
network
low complexity
splunk CWE-502
8.8
2023-08-30 CVE-2023-40597 Path Traversal vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
local
low complexity
splunk CWE-22
8.8
2023-08-30 CVE-2023-40598 Missing Authentication for Critical Function vulnerability in Splunk
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function.
network
low complexity
splunk CWE-306
8.8
2023-06-01 CVE-2023-32707 Unspecified vulnerability in Splunk and Splunk Cloud Platform
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
network
low complexity
splunk
8.8
2023-06-01 CVE-2023-32708 Interpretation Conflict vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.
network
low complexity
splunk CWE-436
8.8