Improper access control in Splunk Enterprise - CVE-2024-53243
Published: December 11, 2024
Vulnerability identifier: #VU101663
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-53243
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improper access restrictions. A remote user can view the mobile alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints.
Affected software
Splunk Enterprise
Splunk Secure Gateway
Splunk Secure Gateway
How to mitigate CVE-2024-53243
Install updates from vendor's website.
Splunk Enterprise - addressed in versions 9.1.7, 9.2.4, 9.3.2
Splunk Secure Gateway - addressed in versions 3.4.262, 3.7.18, 3.8.5
Splunk Secure Gateway - addressed in versions 3.4.262, 3.7.18, 3.8.5