ZeroHour

CVE-2024-23675

CVSS 3.1
6.5 medium
EPSS
<1%p31
Published
()
Modified
Description

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.

Vendors
splunk
Products
cloud, splunk
Weakness
CWE-284, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news