Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Splunk — Vulnerabilities & Security Advisories 283

Browse all 283 CVE security advisories affecting Splunk. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Splunk operates primarily as a data analytics platform designed for searching, monitoring, and analyzing machine-generated big data via a web interface. Its architecture, which integrates complex data ingestion pipelines with extensive third-party app ecosystems, has historically exposed it to diverse vulnerability classes. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from improper input validation or insecure default configurations in its web components. While no single catastrophic breach defines its history, the sheer volume of disclosed flaws highlights systemic risks in its expansive feature set. Security practitioners must rigorously patch these instances, as the platform’s central role in enterprise observability makes unmitigated vulnerabilities particularly impactful. The current count of 155 CVEs underscores the necessity for continuous configuration auditing and strict access controls to maintain integrity within organizations relying on this infrastructure.

CVE ID Title CVSS Severity Published
CVE-2024-36989 Low-privileged user could create notifications in Splunk Web Bulletin Messages — Splunk Enterprise CWE-284 6.5 High 2024-07-01
CVE-2024-36987 Insecure File Upload in the indexing/preview REST endpoint — Splunk Enterprise CWE-434 4.3 Medium 2024-07-01
CVE-2024-29945 Splunk Authentication Token Exposure in Debug Log in Splunk Enterprise — Splunk Enterprise CWE-532 7.2 High 2024-03-27
CVE-2024-29946 Risky command safeguards bypass in Dashboard Examples Hub — Splunk Enterprise CWE-20 8.1 High 2024-03-27
CVE-2023-46230 Sensitive Information Disclosure to Internal Log Files in Splunk Add-on Builder — Splunk Add-on Builder CWE-532 8.2 High 2024-01-30
CVE-2023-46231 Session Token Disclosure to Internal Log Files in Splunk Add-on Builder — Splunk Add-on Builder CWE-532 8.8 Medium 2024-01-30
CVE-2024-23676 Sensitive Information Disclosure of Index Metrics through “mrollup” SPL Command — Splunk Enterprise CWE-20 4.6 Medium 2024-01-22
CVE-2024-23678 Deserialization of Untrusted Data on Splunk Enterprise for Windows through Path Traversal from Separate Disk Partition — Splunk Enterprise CWE-20 7.5 High 2024-01-22
CVE-2024-23677 Server Response Disclosure in RapidDiag Salesforce.com Log File — Splunk Enterprise CWE-532 4.3 Medium 2024-01-22
CVE-2024-23675 Splunk App Key Value Store (KV Store) Improper Handling of Permissions Leads to KV Store Collection Deletion — Splunk Enterprise CWE-284 6.5 Medium 2024-01-22
CVE-2024-22164 Denial of Service of an Investigation in Splunk Enterprise Security through Investigation attachments — Splunk Enterprise Security (ES) CWE-400 4.3 Medium 2024-01-09
CVE-2024-22165 Denial of Service in Splunk Enterprise Security of the Investigations manager through Investigation creation — Splunk Enterprise Security (ES) CWE-20 6.5 Medium 2024-01-09
CVE-2023-46213 Cross-site Scripting (XSS) on “Show Syntax Highlighted” View in Search Page — Splunk Enterprise CWE-79 4.8 Medium 2023-11-16
CVE-2023-46214 Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing — Splunk Enterprise CWE-91 8.0 High 2023-11-16
CVE-2023-40597 Absolute Path Traversal in Splunk Enterprise Using runshellscript.py — Splunk Enterprise CWE-36 7.8 High 2023-08-30
CVE-2023-40596 Splunk Enterprise on Windows Privilege Escalation due to Insecure OPENSSLDIR Build Definition Reference in DLL — Splunk Enterprise CWE-665 7.0 High 2023-08-30
CVE-2023-40594 Denial of Service (DoS) via the ‘printf’ Search Function — Splunk Enterprise CWE-400 6.5 Medium 2023-08-30
CVE-2023-40593 Denial of Service (DoS) in Splunk Enterprise Using a Malformed SAML Request — Splunk Enterprise CWE-400 6.3 Medium 2023-08-30
CVE-2023-4571 Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI) — Splunk ITSI CWE-117 8.6 High 2023-08-30
CVE-2023-40592 Reflected Cross-site Scripting (XSS) on "/app/search/table" web endpoint — Splunk Enterprise CWE-79 8.4 High 2023-08-30
CVE-2023-40595 Remote Code Execution via Serialized Session Payload — Splunk Enterprise CWE-502 8.8 High 2023-08-30
CVE-2023-40598 Command Injection in Splunk Enterprise Using External Lookups — Splunk Enterprise CWE-77 8.5 High 2023-08-30
CVE-2023-3997 Unauthenticated Log Injection In Splunk SOAR — Splunk SOAR (On-premises) CWE-117 8.6 High 2023-07-31
CVE-2023-32709 Low-privileged User can View Hashed Default Splunk Password — Splunk Enterprise CWE-285 4.3 Medium 2023-06-01
CVE-2023-32707 ‘edit_user’ Capability Privilege Escalation — Splunk Enterprise CWE-285 8.8 High 2023-06-01
CVE-2023-32714 Path Traversal in Splunk App for Lookup File Editing — Splunk App for Lookup File Editing CWE-35 8.1 High 2023-06-01
CVE-2023-32713 Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream — Splunk App for Stream CWE-269 7.8 High 2023-06-01
CVE-2023-32712 Unauthenticated Log Injection in Splunk Enterprise — Splunk Enterprise CWE-117 8.6 High 2023-06-01
CVE-2023-32716 Denial of Service via the 'dump' SPL command — Splunk Enterprise CWE-754 6.5 Medium 2023-06-01
CVE-2023-32710 Information Disclosure via the ‘copyresults’ SPL Command — Splunk Enterprise CWE-200 4.8 Medium 2023-06-01

This page lists every published CVE security advisory associated with Splunk. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.