Splunk
cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*
- >= 9.3.0, <= 9.3.2
- >= 9.2.0, <= 9.2.4
- >= 9.1.0, <= 9.1.7
A remote code execution vulnerability has been identified in Splunk Enterprise and Splunk Cloud Platform. In Splunk Enterprise versions prior to 9.3.3, 9.2.5, and 9.1.8, as well as in Splunk Cloud Platform versions prior to 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, low-privileged users without 'admin' or 'power' roles could exploit missing authorization checks to upload files to the '$SPLUNK_HOME/var/run/splunk/apptemp' directory, leading to remote code execution.
Exploitation of this vulnerability allows for remote code execution on the affected system.
Users are advised to upgrade Splunk Enterprise to versions 9.4.0, 9.3.3, 9.2.5, 9.1.8 or higher. For Splunk Cloud Platform, no action is required as Splunk is actively monitoring and patching instances.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.