
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity path traversal vulnerability (CVE-2024-36991) was discovered in Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10. The vulnerability affects the /modules/messaging/ endpoint in Splunk Web, the platform's user interface, and was discovered by Danylo Dmytriiev. The vulnerability received a CVSS v3.1 score of 7.5 (High) and was disclosed on July 1, 2024 (Splunk Advisory).
The vulnerability exists due to a flaw in the Python os.path.join function, which removes the drive letter from path tokens if the drive in the token matches the drive in the built path. This behavior can be exploited through specially crafted GET requests to perform directory traversal, allowing access to files or directories outside the restricted directory. The vulnerability only affects instances where Splunk Web is enabled and does not require authentication for exploitation (HelpNet Security, SonicWall Blog).
Successful exploitation of this vulnerability allows attackers to perform directory listings on the Splunk endpoint and gain unauthorized access to sensitive files in the system. With over 230,000 internet-exposed servers running Splunk, the potential impact is significant. The vulnerability enables attackers to read arbitrary files on the operating system, potentially exposing sensitive information (Cyber Security News).
The vulnerability can be exploited remotely by sending crafted GET requests to vulnerable instances. Multiple proof-of-concept exploits have been published, including one that performs bulk scanning for vulnerable internet-facing endpoints. An attacker only needs remote access to the instance, either over the Internet or a local network, to exploit this vulnerability (HelpNet Security).
Organizations are advised to upgrade to the fixed versions: Splunk Enterprise 9.2.2, 9.1.5, or 9.0.10 or higher. As a temporary workaround, administrators can disable Splunk Web, though upgrading to a patched version is the recommended solution. Splunk's Threat Research team has provided a search query to detect exploitation attempts against the /modules/messaging endpoint (Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."