CVE Vulnerabilities

CVE-2024-36985

Function Call With Incorrectly Specified Argument Value

Published: Jul 01, 2024 | Modified: Mar 07, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.

Weakness

The product calls a function, procedure, or routine, but the caller specifies an argument that contains the wrong value, which may lead to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Splunk Splunk 9.0.0 (including) 9.0.10 (excluding)
Splunk Splunk 9.1.0 (including) 9.1.5 (excluding)
Splunk Splunk 9.2.0 (including) 9.2.2 (excluding)

References