Splunk Cloud Platform 9.1.2308.207

CPE Details

Splunk Cloud Platform 9.1.2308.207
9.1.2308.207
2025-03-13
11h06 +00:00
2025-03-13
11h06 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:splunk:splunk_cloud_platform:9.1.2308.207:*:*:*:*:*:*:*

Informations

Vendor

splunk

Product

splunk_cloud_platform

Version

9.1.2308.207

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-45732 2024-10-14 17h03 +00:00 In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the "nobody" Splunk user in the SplunkDeploymentServerConfig app. This could let the low-privileged user access potentially restricted data.
7.1
Haute
CVE-2024-45740 2024-10-14 17h03 +00:00 In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through Scheduled Views that could result in execution of unauthorized JavaScript code in the browser of a user.
5.4
Moyen
CVE-2024-36990 2024-07-01 16h30 +00:00 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the admin or power Splunk roles could send a specially crafted HTTP POST request to the datamodel/web REST endpoint in Splunk Enterprise, potentially causing a denial of service.
6.5
Moyen
CVE-2024-36994 2024-07-01 16h30 +00:00 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View and Splunk Web Bulletin Messages that could result in execution of unauthorized JavaScript code in the browser of a user.
5.4
Moyen