VDB

GCVE-VVD-NCSC-2024-276

GCVE-VVD-NCSC-2024-276
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published July 2, 2024
De ontwikkelaars van Splunk hebben kwetsbaarheden verholpen in Splunk en Splunk Enterprise.

Weaknesses (CWE)

CWE-476NULL Pointer DereferenceCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-502Deserialization of Untrusted DataCWE-687Function Call With Incorrectly Specified Argument ValueCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-434Unrestricted Upload of File with Dangerous TypeCWE-284Improper Access ControlCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-35Path Traversal: '.../...//'CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-862Missing AuthorizationCWE-204Observable Response Discrepancy

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
splunksplunk_enterprise
splunksplunk
splunksplunk_cloud_platform

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›