#VU93568 Authorization bypass through user-controlled key in Splunk Enterprise - CVE-2024-36986
Published: July 1, 2024
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to improperly imposed security restrictions. A remote user can execute dangerous commands by manipulating the Search ID and using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace.