Lucene search

K
nvd[email protected]NVD:CVE-2024-23675
HistoryJan 22, 2024 - 9:15 p.m.

CVE-2024-23675

2024-01-2221:15:10
CWE-863
CWE-284
web.nvd.nist.gov
1
splunk
enterprise
cve-2024-23675
vulnerability
kv store
permissions
rest api
deletion
collections

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

16.0%

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.

Affected configurations

NVD
Node
splunkcloudRange<9.1.2312.100
OR
splunksplunkRange9.0.09.0.8enterprise
OR
splunksplunkRange9.1.09.1.3enterprise

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.0005 Low

EPSS

Percentile

16.0%

Related for NVD:CVE-2024-23675