Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr9m-r5mr-v22j

Опубликовано: 27 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could edit and delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gateway app created. This is due to missing access control and incorrect ownership of the data in those KVStore collections.

In the affected versions, the nobody user owned the data in the KVStore collections. This meant that there was no specific owner assigned to the data in those collections.

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could edit and delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gateway app created. This is due to missing access control and incorrect ownership of the data in those KVStore collections.

In the affected versions, the nobody user owned the data in the KVStore collections. This meant that there was no specific owner assigned to the data in those collections.

EPSS

Процентиль: 21%
0.0007
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
11 месяцев назад

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could edit and delete other user data in App Key Value Store (KVStore) collections that the Splunk Secure Gateway app created. This is due to missing access control and incorrect ownership of the data in those KVStore collections.<br><br>In the affected versions, the `nobody` user owned the data in the KVStore collections. This meant that there was no specific owner assigned to the data in those collections.

CVSS3: 4.3
fstec
11 месяцев назад

Уязвимость средства регистрации мобильных устройств и развертывания мобильных приложений Splunk Secure Gateway платформы для операционного анализа Splunk Enterprise, связанная с недостатками разграничения доступа, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных из хранилища KV Store (Key Value Store)

EPSS

Процентиль: 21%
0.0007
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284