Improper access control in Splunk Enterprise - CVE-2024-53243

 

Improper access control in Splunk Enterprise - CVE-2024-53243

Published: December 11, 2024


Vulnerability identifier: #VU101663
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-53243
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to improper access restrictions. A remote user can view the mobile alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints.


Affected software

Splunk Enterprise
Splunk Secure Gateway

How to mitigate CVE-2024-53243

Install updates from vendor's website.

Splunk Enterprise - addressed in versions 9.1.7, 9.2.4, 9.3.2
Splunk Secure Gateway - addressed in versions 3.4.262, 3.7.18, 3.8.5

External References

Related Security Bulletins