Splunk
cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*
- >= 9.4.0, <= 9.4.1
- >= 9.3.0, <= 9.3.4
- >= 9.2.0, <= 9.2.6
- >= 9.1.0, <= 9.1.9
A vulnerability exists in Splunk Enterprise versions prior to 9.4.2, 9.3.5, 9.2.7, and 9.1.10, as well as in Splunk Cloud Platform versions prior to 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119. The issue allows low-privileged users, who do not have 'admin' or 'power' roles, to create or modify system source type configurations. This is achieved by sending a specially-crafted payload to the '/servicesNS/nobody/search/admin/sourcetypes/' REST endpoint on the Splunk management port.
Exploitation of this vulnerability could lead to unauthorized creation or modification of system source type configurations, potentially allowing for further exploitation or misconfiguration of the Splunk instance.
Users are advised to upgrade Splunk Enterprise to versions 9.4.2, 9.3.5, 9.2.7, 9.1.10 or higher. For Splunk Cloud Platform, no action is required as Splunk is actively monitoring and patching instances.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.