PT-2026-78732 · Splunk · Splunk Enterprise
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.4.2
Splunk Enterprise versions prior to 10.2.6
Splunk Enterprise versions prior to 10.0.9
Splunk Enterprise versions prior to 9.4.14
Description
A user with a role possessing the
rest properties get capability can read encrypted stored credentials via the Representational State Transfer (REST) API. This occurs because the properties REST endpoint incorrectly requires the rest properties get capability instead of the list storage passwords capability to access stored credentials. Successful exploitation may expose sensitive data protected by these credentials.Recommendations
Update to version 10.4.2 or later.
Update to version 10.2.6 or later.
Update to version 10.0.9 or later.
Update to version 9.4.14 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise