Information Disclosure in Mobile Alert Responses in Splunk Secure Gateway
Published Dec 10, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.29%
Description
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could see alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints due to improper access control.
Affected products
-
Affected
- ≥ 9.1, < 9.1.7
- ≥ 9.2, < 9.2.4
- ≥ 9.3, < 9.3.2
-
Affected
- ≥ 3.4, < 3.4.262
- ≥ 3.7, < 3.7.18
- ≥ 3.8, < 3.8.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Splunk | Splunk Enterprise | unknown | Affected
|
| Splunk | Splunk Secure Gateway | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data