Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpm4-vrgj-h7qc

Опубликовано: 15 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the admin or power Splunk roles, has write permission on the app, and does not hold the high-privilege capability accelerate_datamodel, could turn on or off Data Model Acceleration due to improper access control.

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the admin or power Splunk roles, has write permission on the app, and does not hold the high-privilege capability accelerate_datamodel, could turn on or off Data Model Acceleration due to improper access control.

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
4 месяца назад

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles, has write permission on the app, and does not hold the high-privilege capability `accelerate_datamodel`, could turn on or off Data Model Acceleration due to improper access control.

CVSS3: 4.3
fstec
4 месяца назад

Уязвимость платформы для операционного анализа Splunk Enterprise, связанная с ошибками разграничения доступа, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284