Description
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 15 Oct 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-253 |
Status: PUBLISHED
Assigner: Splunk
Published:
Updated: 2025-02-28T11:03:58.932Z
Reserved: 2024-05-30T16:36:20.999Z
Link: CVE-2024-36985
Updated: 2024-08-02T03:43:50.397Z
Status : Analyzed
Published: 2024-07-01T17:15:06.703
Modified: 2026-06-17T07:37:32.813
Link: CVE-2024-36985
No data.
OpenCVE Enrichment
No data.
Weaknesses