漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise
Vulnerability Description
In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.11, and 9.3.2411.123, a low-privileged user that does not hold the "admin" or "power" Splunk roles could access the `/splunkd/__raw/servicesNS/-/-/configs/conf-passwords` REST API endpoint, which exposes the hashed or plaintext password values that are stored in the passwords.conf configuration file due to improper access control. This vulnerability could allow for the unauthorized disclosure of sensitive credentials.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Splunk Enterprise 信息泄露漏洞
Vulnerability Description
Splunk Enterprise是美国Splunk公司的一套数据收集分析软件。 Splunk Enterprise 10.2.0之前版本、10.0.3之前版本、9.4.9之前版本和9.3.10之前版本以及Splunk Cloud Platform 10.2.2510.5之前版本、10.1.2507.16之前版本、10.0.2503.11之前版本和9.3.2411.123之前版本存在信息泄露漏洞,该漏洞源于访问控制不当,可能导致敏感凭据泄露。
CVSS Information
N/A
Vulnerability Type
N/A