CVE-2024-36990: Denial of Service (DoS) on the datamodel/web REST endpoint
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the admin or power Splunk roles could send a specially crafted HTTP POST request to the datamodel/web REST endpoint in Splunk Enterprise, potentially causing a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36990?
CVE-2024-36990 has a severity rating that indicates it poses a security risk for affected versions of Splunk.
How do I fix CVE-2024-36990?
To fix CVE-2024-36990, upgrade to Splunk Enterprise versions 9.2.2, 9.1.5, or 9.0.10, or Splunk Cloud Platform versions 9.2.2403.100 and later.
Who is affected by CVE-2024-36990?
Authenticated low-privileged users in Splunk Enterprise and Splunk Cloud Platform versions below the specified versions are affected by CVE-2024-36990.
What are the consequences of CVE-2024-36990 exploitation?
Exploitation of CVE-2024-36990 may allow a low-privileged user to send crafted HTTP POST requests, potentially compromising the integrity of the application.
What versions are impacted by CVE-2024-36990?
CVE-2024-36990 affects Splunk Enterprise versions below 9.2.2, 9.1.5, 9.0.10, and Splunk Cloud Platform versions below 9.2.2403.100.