← Back

CVE-2024-29945

nvd nist
Published: Mar 27, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either Splunk Enterprise runs in debug mode or the JsonWebToken component has been configured to log its activity at the DEBUG logging level.

Affected (3)

Products: Splunk: Splunk
1 product
Splunk
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 9.0.0 to 9.0.9
From 9.1.0 to 9.1.4
From 9.2.0 to 9.2.1

References (4)

Source: prodsec@splunk.com
MitigationVendor Advisory
Source: prodsec@splunk.com
Technical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionVendor Advisory

Timeline

No history available yet.