CVE-2024-45738: Sensitive information disclosure in REST_Calls logging channel
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the internal index. This exposure could happen if you configure the Splunk Enterprise RESTCalls log channel at the DEBUG logging level.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45738?
CVE-2024-45738 has been rated as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-45738?
To fix CVE-2024-45738, upgrade to Splunk Enterprise version 9.3.1 or later, 9.2.3 or later, or 9.1.6 or later.
What versions of Splunk are affected by CVE-2024-45738?
CVE-2024-45738 affects Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6.
What is the exploit vector for CVE-2024-45738?
The exploit vector for CVE-2024-45738 involves the configuration of the REST_Calls log channel at the DEBUG logging level, which can expose sensitive HTTP parameters.
What type of data is exposed in CVE-2024-45738?
CVE-2024-45738 potentially exposes sensitive HTTP parameters that may contain confidential information.