CVE-2021-33845: Username enumeration through lockout message in REST API
Published May 6, 2022
·Updated
The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.
Affected Software
1 affected component
Splunk splunk>=8.1.0<8.1.7
Event History
May 6, 2022
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-33845?
CVE-2021-33845 is considered a medium severity vulnerability due to its potential to allow username enumeration.
2
How do I fix CVE-2021-33845?
To mitigate CVE-2021-33845, update your Splunk Enterprise instance to version 8.1.7 or later.
3
Which versions of Splunk Enterprise are affected by CVE-2021-33845?
CVE-2021-33845 affects Splunk Enterprise versions prior to 8.1.7.
4
What type of attack does CVE-2021-33845 enable?
CVE-2021-33845 allows attackers to enumerate valid usernames via error messages from the REST API.
5
Is CVE-2021-33845 related to authentication in Splunk?
Yes, CVE-2021-33845 is related to authentication as it concerns the exposure of usernames during failed login attempts.