CVE-2021-33845
06.05.2022, 17:15
The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| splunk | splunk | 8.1.0 ≤ 𝑥 < 8.1.7 |
𝑥
= Vulnerable software versions
References