VDB
BDU%3A2024-00698
BDU%3A2024-00698
PUBLISHED
CVSS 6.5 MEDIUM
Reported by Splunk · Published January 22, 2024
In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk Enterprise | 9.0, 9.1 |
| Splunk | Splunk Cloud | - |
| Splunk Inc. | Splunk Enterprise, Splunk Cloud Platform | |
| Splunk | Splunk Enterprise | 9.0, 9.1 |
| Splunk | Splunk Cloud | - |
Timeline
- Jan 22, 2024 CVE Published
- Jan 22, 2024 PoC Published
- Feb 7, 2025 CVE Updated
- Feb 28, 2025 PoC Published