CVE-2024-35291: XSS
Published May 27, 2024
·Updated
Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.
Affected Software
1 affected component
Splunk Config Explorer<1.7.16
Event History
May 27, 2024
CVE Published
via MITRE·04:39 AM
Data Sourced
via MITRE·04:39 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35291?
CVE-2024-35291 is classified as a high-severity cross-site scripting vulnerability.
2
How do I fix CVE-2024-35291?
To fix CVE-2024-35291, update Splunk Config Explorer to version 1.7.16 or later immediately.
3
What versions of Splunk Config Explorer are affected by CVE-2024-35291?
CVE-2024-35291 affects all versions of Splunk Config Explorer prior to 1.7.16.
4
What are the potential impacts of exploiting CVE-2024-35291?
Exploiting CVE-2024-35291 may allow attackers to execute arbitrary scripts in the web browsers of users.
5
Is there any workaround for CVE-2024-35291?
There are no reported workarounds for CVE-2024-35291; updating to the latest version is required to mitigate the vulnerability.