Beveiligingsadvies

CVE-2021-33845

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-05-06 16:35:58
Laatst bijgewerkt 2024-08-04 00:05:51
Toegewezen door Splunk
CVSS-score 5.3
Status PUBLISHED

Beschrijving

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.