Splunk Security Updates – 31 March 2024

Splunk has released security updates to fix several vulnerabilities across multiple Splunk products.

The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, or bypass security restrictions caused by the lack of protections for risky SPL commands and persuade the victim to initiate a request within their browser.

The addressed vulnerabilities:

1. Splunk Enterprise Security Bypass Vulnerability (CVE-2024-29946):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Bypass Security

2. Splunk Enterprise Information Disclosure Vulnerability (CVE-2024-29945):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Obtain Information

The affected products:

  • Splunk Enterprise from 9.0 before 9.0.9.
  • Splunk Enterprise 9.1 before 9.1.4.
  • Splunk Enterprise from 9.2 before 9.2.1.
Vulnerabilities
  • CVE-2024-29946
  • CVE-2024-29945
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Splunk Security Updates

References