CVE-2024-53246Cleartext Transmission of Sensitive Info in Cloud Platform

Severity
7.5HIGHNVD
CNA5.3
EPSS
0.1%
top 78.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10

Description

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information. The vulnerability requires the exploitation of another vulnerability, such as a Risky Commands Bypass, for successful exploitation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5splunk/splunk_cloud_platform9.3.24089.3.2408.101+3
NVDsplunk/splunk_cloud_platform9.1.23129.1.2312.206+3
CVEListV5splunk/splunk_enterprise9.39.3.2+2
NVDsplunk/splunk9.1.09.1.7+2

🔴Vulnerability Details

2
CVEList
Sensitive Information Disclosure through SPL commands2024-12-10
GHSA
GHSA-99f4-87g4-qw2h: In Splunk Enterprise versions below 92024-12-10
CVE-2024-53246 — Splunk Cloud Platform vulnerability | cvebase