{ "id": "CVE-2024-53245", "sourceIdentifier": "prodsec@splunk.com", "published": "2024-12-10T18:15:41.397", "lastModified": "2024-12-10T18:15:41.397", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the \u201cadmin\u201c or \u201cpower\u201c Splunk roles, that has a username with the same name as a role with read access to dashboards, could see the dashboard name and the dashboard XML by cloning the dashboard." }, { "lang": "es", "value": "En las versiones de Splunk Enterprise anteriores a 9.3.0, 9.2.4 y 9.1.7 y las versiones de Splunk Cloud Platform anteriores a 9.1.2312.206, un usuario con privilegios bajos que no tenga los roles de Splunk \u201cadmin\u201d o \u201cpower\u201d, que tenga un nombre de usuario con el mismo nombre que un rol con acceso de lectura a los paneles, podr\u00eda ver el nombre del panel y el XML del panel al clonar el panel." } ], "metrics": { "cvssMetricV31": [ { "source": "prodsec@splunk.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N", "baseScore": 3.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE" }, "exploitabilityScore": 1.6, "impactScore": 1.4 } ] }, "weaknesses": [ { "source": "prodsec@splunk.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-200" } ] } ], "references": [ { "url": "https://advisory.splunk.com/advisories/SVD-2024-1203", "source": "prodsec@splunk.com" } ] }