Improper access control in Splunk Enterprise - CVE-2024-45735
Published: October 15, 2024
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and view the App Key Value Store (KV Store) deployment configuration and public/private keys in the Splunk Secure Gateway App.
Affected software
Splunk Secure Gateway
How to mitigate CVE-2024-45735
Splunk Secure Gateway - addressed in versions 3.4.259, 3.6.17, 3.7.0