CVE-2024-45732: Low-privileged user could run search as nobody in SplunkDeploymentServerConfig app
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the "nobody" Splunk user in the SplunkDeploymentServerConfig app. This could let the low-privileged user access potentially restricted data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45732?
CVE-2024-45732 is considered a low-severity vulnerability affecting specific Splunk versions.
How do I fix CVE-2024-45732?
To resolve CVE-2024-45732, upgrade your Splunk Enterprise or Splunk Cloud Platform to the latest version specified in the advisory.
Which versions are affected by CVE-2024-45732?
CVE-2024-45732 affects Splunk Enterprise versions below 9.3.1 and 9.2.0 below 9.2.3, as well as specific Splunk Cloud Platform versions.
What type of user can exploit CVE-2024-45732?
CVE-2024-45732 can be exploited by low-privileged users who do not hold the 'admin' or 'power' roles in Splunk.
Is there a patch available for CVE-2024-45732?
Yes, patches for CVE-2024-45732 are included in the latest releases of the affected Splunk versions.