CVE-2024-45736: Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted "INGESTEVAL" parameter as part of a Field Transformation which could crash the Splunk daemon (splunkd).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45736?
CVE-2024-45736 has a low severity rating.
How do I fix CVE-2024-45736?
To mitigate CVE-2024-45736, ensure that you upgrade to Splunk Enterprise version 9.3.1 or higher, or the appropriate version of Splunk Cloud Platform.
Who is affected by CVE-2024-45736?
CVE-2024-45736 affects low-privileged users in Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 as well as several versions of Splunk Cloud Platform.
What type of users are impacted by CVE-2024-45736?
CVE-2024-45736 specifically impacts low-privileged users that do not hold the "admin" or "power" roles in Splunk.
What exploitation technique is associated with CVE-2024-45736?
CVE-2024-45736 can be exploited by crafting a search query with an improperly formatted "IN" clause.