Resource exhaustion in Splunk Enterprise - CVE-2024-45736
Published: October 15, 2024
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote user can initiate a search query with an improperly-formatted “INGEST_EVAL” parameter as part of a Field Transformation and crash the Splunk daemon (splunkd).