CVE-2010-2429: XSS
Published Jun 23, 2010
·Updated
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer in a "404 Not Found" response.
Affected Software
16 affected components
Splunk splunk=4.0
Splunk splunk=4.0.1
Splunk splunk=4.0.2
Splunk splunk=4.0.3
Splunk splunk=4.0.4
Splunk splunk=4.0.5
Splunk splunk=4.0.6
Splunk splunk=4.0.7
Splunk splunk=4.0.8
Splunk splunk=4.0.9
Splunk splunk=4.0.10
Splunk splunk=4.0.11
Splunk splunk=4.1
Splunk splunk=4.1.1
Splunk splunk=4.1.2
Microsoft Internet Explorer
Remediation
Patch Available
Event History
Jun 23, 2010
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
Description
Jun 24, 2010
Data Sourced
12:17 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2429?
CVE-2010-2429 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2010-2429?
To fix CVE-2010-2429, upgrade Splunk to version 4.1.3 or later.
3
What versions of Splunk are affected by CVE-2010-2429?
CVE-2010-2429 affects Splunk versions 4.0 through 4.1.2.
4
What kind of attack does CVE-2010-2429 facilitate?
CVE-2010-2429 facilitates cross-site scripting (XSS) attacks via manipulated HTTP Referer headers.
5
Is Internet Explorer a factor in the CVE-2010-2429 vulnerability?
Yes, CVE-2010-2429 specifically affects users of Internet Explorer when accessing vulnerable versions of Splunk.