Security Advisory

CVE-2024-36991

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-07-01 16:31:03
Last updated 2025-02-28 11:03:48
Assigner Splunk
State PUBLISHED

Description

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.