← Back

CVE-2024-45737

nvd nist
Published: Oct 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
3.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Exploitability: 2.1 / Impact: 1.4
Source: NVD

Description

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).

Affected (5)

2 products
Splunk
Splunk Cloud Platform
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Splunk
From 9.1.0 to 9.1.6
From 9.2.0 to 9.2.3
Version 9.3.0
Splunk
From 9.1.2312 to 9.1.2312.204
From 9.2.2403.102 to 9.2.2403.108

References (2)

Timeline

No history available yet.