CVE-2024-36982
EUVD-2024-3637001.07.2024, 17:15
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| splunk | cloud | 9.1.2308 ≤ 𝑥 < 9.1.2308.207 |
| splunk | cloud | 9.1.2312.100 ≤ 𝑥 < 9.1.2312.109 |
| splunk | splunk | 9.0.0 ≤ 𝑥 < 9.0.10 |
| splunk | splunk | 9.1.0 ≤ 𝑥 < 9.1.5 |
| splunk | splunk | 9.2.0 ≤ 𝑥 < 9.2.2 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| splunk | splunk_enterprise | 9.2 ≤ 𝑥 < 9.2.2 | ADP |
| splunk | splunk_enterprise | 9.1 ≤ 𝑥 < 9.1.5 | ADP |
| splunk | splunk_enterprise | 9.0 ≤ 𝑥 < 9.0.10 | ADP |
| splunk | splunk_cloud_platform | 9.1.2312 ≤ 𝑥 < 9.1.2312.109 | ADP |
| splunk | splunk_cloud_platform | 9.1.2308 ≤ 𝑥 < 9.1.2308.207 | ADP |
Common Weakness Enumeration