In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Splunk

Published: 2024-03-27T16:15:59.872Z

Updated: 2024-07-03T16:06:37.123Z

Reserved: 2024-03-21T21:09:44.795Z


Link: CVE-2024-29946

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2024-03-27T17:15:54.273

Modified: 2024-04-10T01:15:18.873


Link: CVE-2024-29946

JSON object: View

cve-icon Redhat Information

No data.