CVE-2024-36985
HIGHAuthenticated RCE in Splunk (splunk_archiver app)
Title source: metasploitExploitation Summary
EIP tracks 2 public exploits for CVE-2024-36985.
PoCs published by LittleSuRii, Maksim Rogov, Alex Hordijk, psytester, including Metasploit module exploits/linux/http/splunk_auth_rce_cve_2024_36985.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2024-36985, targeting Splunk Enterprise via the 'copybuckets' custom search command to achieve remote code execution. The exploit authenticates to Splunk, constructs a malicious SPL query with a base64-encoded reverse shell payload, and triggers execution via the REST API.
Description
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.
Exploits (2)
This repository contains a functional Python exploit for CVE-2024-36985, targeting Splunk Enterprise via the 'copybuckets' custom search command to achieve remote code execution. The exploit authenticates to Splunk, constructs a malicious SPL query with a base64-encoded reverse shell payload, and triggers execution via the REST API.
This Metasploit module exploits CVE-2024-36985, an authenticated RCE vulnerability in Splunk Enterprise's splunk_archiver app. It leverages unsafe use of the | copybuckets lookup function to execute arbitrary commands via the sudobash helper script.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H