ZeroHour

CVE-2022-26070

CVSS 3.1
4.3 medium
EPSS
<1%p49
Published
()
Modified
Description

When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.

Vendors
splunk
Products
splunk
Weakness
CWE-200, CWE-209
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.