Splunk Splunk Enterprise是美国Splunk公司的日志分析系统。 Splunk Enterprise存在跨站请求伪造漏洞,该漏洞源于Splunk Web中的部署服务器端点未验证GET请求上的跨站请求伪造令牌,且调用者提供的输入未被正确清理即放入SPL搜索,可能导致攻击者诱使用户运行任意SPL搜索,从而访问存储的凭据和索引数据。以下版本受到影响:10.4.1之前版本、10.2.5之前版本、10.0.8之前版本、9.4.13之前版本、10.5.2605.0之前版本、10.4.2604.7
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Cloud Platform | 10.5.2605< 10.5.2605.0 |
affected |
10.4.2604< 10.4.2604.7 |
affected | ||
10.3.2512< 10.3.2512.16 |
affected | ||
10.2.2510< 10.2.2510.18 |
affected | ||
10.1.2507< 10.1.2507.24 |
affected | ||
| Splunk | Splunk Enterprise | 10.4< 10.4.1 |
affected |
10.2< 10.2.5 |
affected | ||
10.0< 10.0.8 |
affected | ||
9.4< 9.4.13 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4 ~ 10.4.1 | - |
|
| Splunk | Splunk Cloud Platform | 10.5.2605 ~ 10.5.2605.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20297 | 7.2 HIGH | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enter |
| CVE-2026-20298 | 5.3 MEDIUM | Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Ent |
No comments yet