CVE-2018-11409
MEDIUM EXPLOITED NUCLEISplunk < 7.0.1 - Unauthenticated Information Disclosure via Server Info Endpoint
Title source: llmExploitation Summary
CVE-2018-11409 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including KoF2002, n00bhaxor, KOF2002, h00die, including a Metasploit module auxiliary/gather/splunk_raw_server_info.
A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Splunk versions up to 7.0.1. It leverages an unauthenticated endpoint to retrieve sensitive server information, including license keys, via a crafted URL.
Description
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
Exploits (2)
This exploit demonstrates an information disclosure vulnerability in Splunk versions up to 7.0.1. It leverages an unauthenticated endpoint to retrieve sensitive server information, including license keys, via a crafted URL.
This Metasploit module exploits an information disclosure vulnerability in Splunk versions 6.2.3 through 7.0.1 by querying the `/__raw/services/server/info/server-info` endpoint. It supports both authenticated and unauthenticated access, depending on the version, and retrieves sensitive system information.
Nuclei Templates (1)
http.title:"login - splunk"
title="login - splunk"
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N