CVE-2024-53245
CVSS V2 None
CVSS V3 None
Description
In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles, that has a username with the same name as a role with read access to dashboards, could see the dashboard name and the dashboard XML by cloning the dashboard.
Overview
- CVE ID
- CVE-2024-53245
- Assigner
- Splunk
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-12-10T18:00:33.254Z
- Last Modified Date
- 2024-12-10T21:14:03.947Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://advisory.splunk.com/advisories/SVD-2024-1203 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-53245 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-53245 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-11 13:55:53 | Added to TrackCVE |