CVE-2021-33845

MEDIUM

Splunk 8.1.0-8.1.7 - Username Enumeration via Lockout Error Message

Title source: llm
STIX 2.1

Description

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-203
Status published
Products (1)
splunk/splunk 8.1.0 - 8.1.7
Published May 06, 2022
Tracked Since Feb 18, 2026