CVE Vulnerabilities

CVE-2024-36982

NULL Pointer Dereference

Published: Jul 01, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Cloud Splunk 9.1.2308 (including) 9.1.2308.207 (excluding)
Cloud Splunk 9.1.2312.100 (including) 9.1.2312.109 (excluding)
Splunk Splunk 9.0.0 (including) 9.0.10 (excluding)
Splunk Splunk 9.1.0 (including) 9.1.5 (excluding)
Splunk Splunk 9.2.0 (including) 9.2.2 (excluding)

Potential Mitigations

References