CVE-2024-36997

HIGH

Splunk < 9.0.10, 9.1.5-9.1.2312, < 9.2.2 - Authenticated Stored Cross-Site Scripting via conf-web/settings REST Endpoint

Title source: llm
STIX 2.1

Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a persistent cross-site scripting (XSS) exploit.

Scores

CVSS v3 8.1
EPSS 0.0105
EPSS Percentile 77.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
splunk/splunk 9.0.0 - 9.0.10
splunk/splunk_cloud_platform 9.1.2312 - 9.1.2312.100
Published Jul 01, 2024
Tracked Since Feb 18, 2026