Splunk through 7.0.1 is susceptible to information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view