CVE-2024-23677: Server Response Disclosure in RapidDiag Salesforce.com Log File
Published Jan 22, 2024
·Updated
In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.
Affected Software
2 affected components
Splunk Cloud<9.0.2208
Splunk splunk>=9.0.0<9.0.8
Event History
Jan 22, 2024
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23677?
CVE-2024-23677 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-23677?
To fix CVE-2024-23677, upgrade your Splunk Enterprise or Splunk Cloud to version 9.0.8 or later.
3
What versions of Splunk are affected by CVE-2024-23677?
CVE-2024-23677 affects all versions of Splunk Enterprise below 9.0.8 and Splunk Cloud versions prior to 9.0.2208.
4
What exposure risk does CVE-2024-23677 pose?
CVE-2024-23677 may expose sensitive server responses from external applications in log files.
5
Is CVE-2024-23677 related to specific Splunk utilities?
Yes, CVE-2024-23677 specifically affects the Splunk RapidDiag utility.