CVE-2024-36991
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
7.5
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2024-07-01
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-35CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| splunk | splunk | >= 9.0.0, < 9.0.10 |
| splunk | splunk | >= 9.1.0, < 9.1.5 |
| splunk | splunk | >= 9.2.0, < 9.2.2 |
| microsoft | windows | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-36991