CVE-2024-36983
From there, the user could execute arbitrary code on the Splunk platform Instance.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- splunk/splunk · splunk/splunk cloud platform
- Source
- prodsec@splunk.com
References
- https://advisory.splunk.com/advisories/SVD-2024-0703Vendor Advisory
- https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/Tool Signature
- https://advisory.splunk.com/advisories/SVD-2024-0703Vendor Advisory
- https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/Tool Signature
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.