#VU98535 Resource exhaustion in Splunk Enterprise - CVE-2024-45736
Published: October 15, 2024
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote user can initiate a search query with an improperly-formatted “INGEST_EVAL” parameter as part of a Field Transformation and crash the Splunk daemon (splunkd).