CVE-2024-36989

HIGH

Splunk Enterprise <9.2.2, <9.1.5, <9.0.10 & Splunk Cloud <9.1.2312.200 - Bulletin Message Injection

Title source: llm
STIX 2.1

Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
splunk/cloud 9.1.2312 - 9.1.2312.200
splunk/splunk 9.0.0 - 9.0.10
Published Jul 01, 2024
Tracked Since Feb 18, 2026