Fiche vulnérabilité
CVE-2024-23678 : faille élevée splunk splunk (CVSS 8.8)
Description
In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 22 janv. 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- splunk splunk