PT-2026-48492 · Splunk · Splunk Cloud Platform+2
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.2.4
Splunk Enterprise versions prior to 10.0.7
Splunk Enterprise versions prior to 9.4.12
Splunk Enterprise versions prior to 9.3.13
Splunk Cloud Platform versions prior to 10.4.2604.3
Splunk Cloud Platform versions prior to 10.3.2512.12
Splunk Cloud Platform versions prior to 10.2.2510.14
Splunk Cloud Platform versions prior to 10.1.2507.22
Splunk Cloud Platform versions prior to 9.3.2411.132
Description
A low-privileged user without "admin" or "power" roles can send server-side requests to arbitrary internal destinations using the Dashboard Studio PDF export feature. This occurs because the trusted-domain validation employs a prefix match that can be bypassed using attacker-controlled subdomains. Additionally, the PDF export service automatically follows HTTP redirects without re-validating the redirect targets against the allowlist.
Recommendations
Update to version 10.2.4 or newer.
Update to version 10.0.7 or newer.
Update to version 9.4.12 or newer.
Update to version 9.3.13 or newer.
Update to version 10.4.2604.3 or newer.
Update to version 10.3.2512.12 or newer.
Update to version 10.2.2510.14 or newer.
Update to version 10.1.2507.22 or newer.
Update to version 9.3.2411.132 or newer.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Cloud Platform
Splunk Enterprise
Splunk