CVE-2010-2504

EUVD-2010-2508
Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allows remote authenticated users to obtain sensitive information via HTTP header injection, aka SPL-31066.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
splunksplunk
4.0
splunksplunk
4.0.1
splunksplunk
4.0.2
splunksplunk
4.0.3
splunksplunk
4.0.4
splunksplunk
4.0.5
splunksplunk
4.0.6
splunksplunk
4.0.7
splunksplunk
4.0.8
splunksplunk
4.0.9
splunksplunk
4.0.10
splunksplunk
4.1
splunksplunk
4.1.1
𝑥
= Vulnerable software versions