CVE-2017-5607

Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 LOW
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
splunksplunk
𝑥
≤ 6.5.1
splunksplunk
5.0.0 ≤
𝑥
< 5.0.18
splunksplunk
6.0.0 ≤
𝑥
< 6.0.14
splunksplunk
6.1.0 ≤
𝑥
< 6.1.13
splunksplunk
6.2.0 ≤
𝑥
< 6.2.13.1
splunksplunk
6.3.0 ≤
𝑥
< 6.3.10
splunksplunk
6.4.0 ≤
𝑥
< 6.4.6
splunksplunk
6.5.0 ≤
𝑥
< 6.5.3
𝑥
= Vulnerable software versions