Security Advisory

CVE-2024-45738

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-10-14 17:03:38
Last updated 2025-02-28 11:03:47
Assigner Splunk
State PUBLISHED

Description

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG logging level.