← Back

CVE-2024-36996

nvd nist
Published: Jul 1, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance when they attempt to log in. This disclosure could then lead to additional brute-force password-guessing attacks. This vulnerability would require that the Splunk platform instance uses the Security Assertion Markup Language (SAML) authentication scheme.

Affected (4)

2 products
Splunk
Splunk Cloud Platform
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 9.0.0 to 9.0.10
From 9.1.0 to 9.1.5
From 9.2.0 to 9.2.2
From 9.1.2312 to 9.1.2312.109

References (2)

Source: prodsec@splunk.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.