CVE-2024-36983

EUVD-2024-36371
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
splunksplunk
9.0.0 ≤
𝑥
< 9.0.10
splunksplunk
9.1.0 ≤
𝑥
< 9.1.5
splunksplunk
9.2.0 ≤
𝑥
< 9.2.2
splunksplunk_cloud_platform
9.1.2308 ≤
𝑥
< 9.1.2308.207
splunksplunk_cloud_platform
9.1.2312 ≤
𝑥
< 9.1.2312.109
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
splunksplunk
9.2 ≤
𝑥
< 9.2.2
ADP
splunksplunk
9.1 ≤
𝑥
< 9.1.5
ADP
splunksplunk
9.0 ≤
𝑥
< 9.0.10
ADP
splunksplunk_cloud_platform
9.1.2312 ≤
𝑥
< 9.1.2312.109
ADP
splunksplunk_cloud_platform
9.1.2308 ≤
𝑥
< 9.1.2308.207
ADP