Persistent Cross-site Scripting (XSS) in Dashboard Elements
Published Jul 1, 2024
5.4
MEDIUMCVSS 3.1
EPSS 0.31%
Description
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View that could result in execution of unauthorized JavaScript code in the browser of a user. The “url” parameter of the Dashboard element does not have proper input validation to reject invalid URLs, which could lead to a Persistent Cross-site Scripting (XSS) exploit.
Affected products
-
- Version 9.1.2308StatusaffectedConstraints<9.1.2308.207
- Version 9.1.2312StatusaffectedConstraints<9.1.2312.200
- Version
-
- Version 9.0StatusaffectedConstraints<9.0.10
- Version 9.1StatusaffectedConstraints<9.1.5
- Version 9.2StatusaffectedConstraints<9.2.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Splunk | Splunk Cloud Platform | n/a |
| ||||||||||||
| Splunk | Splunk Enterprise | n/a |
|
- ≥ 9.0.0 · < 9.0.10
- ≥ 9.1.0 · < 9.1.5
- ≥ 9.2.0 · < 9.2.2
- ≥ 9.1.2308 · < 9.1.2308.207
- ≥ 9.1.2312 · < 9.1.2312.200
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://advisory.splunk.com/advisories/SVD-2024-0712 Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-36379 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://advisory.splunk.com/advisories/SVD-2024-0712 | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-36379 | Advisory |
Change history (0)
No recorded changes yet.