2024-12-08 03:06:42 +00:00

72 lines
2.5 KiB
JSON

{
"id": "CVE-2024-36997",
"sourceIdentifier": "prodsec@splunk.com",
"published": "2024-07-01T17:15:09.143",
"lastModified": "2024-11-21T09:23:00.207",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a persistent cross-site scripting (XSS) exploit."
},
{
"lang": "es",
"value": "En las versiones de Splunk Enterprise inferiores a 9.2.2, 9.1.5 y 9.0.10 y en las versiones de Splunk Cloud Platform inferiores a 9.1.2312, un usuario administrador podr\u00eda almacenar y ejecutar c\u00f3digo JavaScript arbitrario en el contexto del navegador de otro usuario de Splunk a trav\u00e9s de conf-web/settings endpoint REST. Potencialmente, esto podr\u00eda provocar un exploit de cross-site scripting (XSS) persistente."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "prodsec@splunk.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 1.7,
"impactScore": 5.8
}
]
},
"weaknesses": [
{
"source": "prodsec@splunk.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://advisory.splunk.com/advisories/SVD-2024-0717",
"source": "prodsec@splunk.com"
},
{
"url": "https://research.splunk.com/application/ed1209ef-228d-4dab-9856-be9369925a5c",
"source": "prodsec@splunk.com"
},
{
"url": "https://advisory.splunk.com/advisories/SVD-2024-0717",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://research.splunk.com/application/ed1209ef-228d-4dab-9856-be9369925a5c",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}