← Back

CVE-2021-31559

nvd nist
Published: May 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders.

Affected (2)

Products: Splunk: Splunk
1 product
Splunk
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 8.1.0 to 8.1.5
Version 8.2.0

References (2)

Timeline

No history available yet.