VDB

BDU%3A2024-00698

BDU%3A2024-00698 PUBLISHED CVSS 6.5 MEDIUM

Reported by Splunk · Published January 22, 2024

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
SplunkSplunk Enterprise9.0, 9.1
SplunkSplunk Cloud-
Splunk Inc.Splunk Enterprise, Splunk Cloud Platform
SplunkSplunk Enterprise9.0, 9.1
SplunkSplunk Cloud-

Timeline

  • Jan 22, 2024 CVE Published
  • Jan 22, 2024 PoC Published
  • Feb 7, 2025 CVE Updated
  • Feb 28, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›