First published: Mon Jan 22 2024(Updated: )
In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.
Credit: prodsec@splunk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Splunk Cloud Platform | <9.0.2208 | |
Splunk | >=9.0.0<9.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23677 is classified as a medium severity vulnerability.
To fix CVE-2024-23677, upgrade your Splunk Enterprise or Splunk Cloud to version 9.0.8 or later.
CVE-2024-23677 affects all versions of Splunk Enterprise below 9.0.8 and Splunk Cloud versions prior to 9.0.2208.
CVE-2024-23677 may expose sensitive server responses from external applications in log files.
Yes, CVE-2024-23677 specifically affects the Splunk RapidDiag utility.