Описание
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.
Уязвимые конфигурации
Конфигурация 1Версия до 8.1.0 (исключая)
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 49%
0.00263
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200
CWE-209
Связанные уязвимости
CVSS3: 4.3
github
почти 4 года назад
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.
EPSS
Процентиль: 49%
0.00263
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200
CWE-209