CVE-2024-36994: Persistent Cross-site Scripting (XSS) in Dashboard Elements
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View and Splunk Web Bulletin Messages that could result in execution of unauthorized JavaScript code in the browser of a user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36994?
CVE-2024-36994 is classified as a low-severity vulnerability affecting specific versions of Splunk Enterprise and Splunk Cloud Platform.
How do I fix CVE-2024-36994?
To fix CVE-2024-36994, upgrade Splunk Enterprise to versions 9.2.2, 9.1.5, or 9.0.10, and Splunk Cloud Platform to versions 9.1.2312.200 or 9.1.2308.207.
Who is affected by CVE-2024-36994?
CVE-2024-36994 affects low-privileged users without admin or power roles in the specified versions of Splunk.
What types of systems are impacted by CVE-2024-36994?
CVE-2024-36994 impacts Splunk Enterprise and Splunk Cloud Platform versions prior to the specified releases.
Can CVE-2024-36994 be exploited remotely?
CVE-2024-36994 may be exploited remotely by low-privileged users through crafted payloads in the View and Splunk Web Bulletin Message.