← Back

CVE-2024-45736

nvd nist
Published: Oct 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted "INGEST_EVAL" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) which could crash the Splunk daemon (splunkd).

Affected (6)

2 products
Splunk
Splunk Cloud Platform
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 9.1.0 to 9.1.6
From 9.2.0 to 9.2.3
Version 9.3.0
Splunk
From 9.1.2312 to 9.1.2312.111
From 9.1.2312.200 to 9.1.2312.204
From 9.2.2403.100 to 9.2.2403.107

References (2)

Timeline

No history available yet.