CVE Vulnerabilities

CVE-2010-3323

Published: Sep 14, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Splunk 4.0.0 through 4.1.4 allows remote attackers to conduct session hijacking attacks and obtain the splunkd session key via vectors related to the SPLUNKD_SESSION_KEY parameter.

Affected Software

Name Vendor Start Version End Version
Splunk Splunk 4.0 (including) 4.0 (including)
Splunk Splunk 4.0.1 (including) 4.0.1 (including)
Splunk Splunk 4.0.2 (including) 4.0.2 (including)
Splunk Splunk 4.0.3 (including) 4.0.3 (including)
Splunk Splunk 4.0.4 (including) 4.0.4 (including)
Splunk Splunk 4.0.5 (including) 4.0.5 (including)
Splunk Splunk 4.0.6 (including) 4.0.6 (including)
Splunk Splunk 4.0.7 (including) 4.0.7 (including)
Splunk Splunk 4.0.8 (including) 4.0.8 (including)
Splunk Splunk 4.0.9 (including) 4.0.9 (including)
Splunk Splunk 4.0.10 (including) 4.0.10 (including)
Splunk Splunk 4.0.11 (including) 4.0.11 (including)
Splunk Splunk 4.1 (including) 4.1 (including)
Splunk Splunk 4.1.1 (including) 4.1.1 (including)
Splunk Splunk 4.1.2 (including) 4.1.2 (including)
Splunk Splunk 4.1.3 (including) 4.1.3 (including)
Splunk Splunk 4.1.4 (including) 4.1.4 (including)

References