CVE-2024-23676: Sensitive Information Disclosure of Index Metrics through “mrollup” SPL Command
Published Jan 22, 2024
·Updated
In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user to exploit.
Affected Software
3 affected components
Splunk Cloud<9.1.2308.200
Splunk splunk>=9.0.0<9.0.8
Splunk splunk>=9.1.0<9.1.3
Event History
Jan 22, 2024
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23676?
CVE-2024-23676 is rated as a medium severity vulnerability.
2
How do I fix CVE-2024-23676?
To fix CVE-2024-23676, upgrade Splunk to version 9.0.8 or 9.1.3 or later.
3
Who is affected by CVE-2024-23676?
CVE-2024-23676 affects Splunk versions below 9.0.8 and 9.1.3.
4
What type of vulnerability is CVE-2024-23676?
CVE-2024-23676 is an authorization bypass vulnerability.
5
Does CVE-2024-23676 require user interaction to exploit?
Yes, CVE-2024-23676 requires user interaction from a high-privileged user to be exploited.