Aller au contenu

Fiche vulnérabilité

CVE-2024-23678 : faille élevée splunk splunk (CVSS 8.8)

Description

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
22 janv. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • splunk splunk

Références

Rechercher une autre vulnérabilité dans la base CVE