PT-2026-20473 · Splunk · Splunk Enterprise+1
CVE-2026-20144
·
Publicado
2026-02-18
·
Atualizado
2026-02-24
CVSS v3.1
6.8
Média
| Vetor | AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11
Splunk Cloud Platform versions prior to 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120
Description
A user with access to the Splunk
internal index within a Splunk Search Head Cluster (SHC) deployment may be able to view Security Assertion Markup Language (SAML) configurations in plain text within the conf.log file. This includes configurations for Attribute Query Requests (AQRs) or Authentication extensions, depending on which feature is configured.Recommendations
Update Splunk Enterprise to version 10.2.0 or later.
Update Splunk Enterprise to version 10.0.2 or later.
Update Splunk Enterprise to version 9.4.7 or later.
Update Splunk Enterprise to version 9.3.8 or later.
Update Splunk Enterprise to version 9.2.11 or later.
Update Splunk Cloud Platform to version 10.2.2510.0 or later.
Update Splunk Cloud Platform to version 10.1.2507.11 or later.
Update Splunk Cloud Platform to version 10.0.2503.9 or later.
Update Splunk Cloud Platform to version 9.3.2411.120 or later.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Splunk Cloud Platform
Splunk Enterprise