Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mmpr-prc4-7pjc

Опубликовано: 07 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search Bucket Copy Trigger within the Splunk Archiver application. This is because of missing access controls in the saved searches for this app.

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search Bucket Copy Trigger within the Splunk Archiver application. This is because of missing access controls in the saved searches for this app.

EPSS

Процентиль: 12%
0.0004
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
7 месяцев назад

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search `Bucket Copy Trigger` within the Splunk Archiver application. This is because of missing access controls in the saved searches for this app.

EPSS

Процентиль: 12%
0.0004
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284