Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6q6w-qw52-9q3j

Опубликовано: 17 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration.

The vulnerability exists because of an insecure default domain allowlist in the Splunk AI Toolkit, which does not restrict outbound AI agent requests to approved external domains.

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration.

The vulnerability exists because of an insecure default domain allowlist in the Splunk AI Toolkit, which does not restrict outbound AI agent requests to approved external domains.

EPSS

Процентиль: 12%
0.00217
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 месяцев назад

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration. The vulnerability exists because of an insecure default domain allowlist in the Splunk AI Toolkit, which does not restrict outbound AI agent requests to approved external domains.

CVSS3: 4.3
fstec
около 2 месяцев назад

Уязвимость программного средства для работы с алгоритмами машинного обучения Splunk AI Tookit (AITK) (ранее Splunk Machine Learning Toolkit (MLTK)), связанная с небезопасной инициализацией ресурса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 12%
0.00217
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-1188