CVE Vulnerabilities

CVE-2024-23678

Published: Jan 22, 2024 | Modified: Apr 10, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.

Affected Software

Name Vendor Start Version End Version
Splunk Splunk 9.0.0 (including) 9.0.8 (excluding)
Splunk Splunk 9.1.0 (including) 9.1.3 (excluding)

References