CVE-2024-36985: Remote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk Enterprise
Published Jul 1, 2024
·Updated
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunkarchiver“ application.
Affected Software
4 affected components
Splunk Splunk Enterprise<9.2.2, <9.1.5, <9.0.10
Splunk splunk>=9.0.0<9.0.10
Splunk splunk>=9.1.0<9.1.5
Splunk splunk>=9.2.0<9.2.2
Event History
Jul 1, 2024
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36985?
CVE-2024-36985 is classified as a low severity vulnerability.
2
How do I fix CVE-2024-36985?
To mitigate CVE-2024-36985, upgrade Splunk Enterprise to version 9.2.2 or higher, or 9.1.5 or higher, or 9.0.10 or higher.
3
Who is affected by CVE-2024-36985?
CVE-2024-36985 affects low-privileged users in Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10.
4
What type of vulnerability is CVE-2024-36985?
CVE-2024-36985 is a Remote Code Execution vulnerability.
5
Which application is related to CVE-2024-36985?
CVE-2024-36985 is related to the 'splunk_archiver' application in Splunk Enterprise.