CVE-2024-53243: Information Disclosure in Mobile Alert Responses in Splunk Secure Gateway
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could see alert search query responses using Splunk Secure Gateway App Key Value Store (KVstore) collections endpoints due to improper access control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53243?
CVE-2024-53243 is considered a low-severity vulnerability affecting Splunk Enterprise and Splunk Secure Gateway app.
How do I fix CVE-2024-53243?
To fix CVE-2024-53243, upgrade to Splunk Enterprise version 9.3.2 or higher, or to version 3.2.462 or higher of the Splunk Secure Gateway app.
Who is affected by CVE-2024-53243?
CVE-2024-53243 affects low-privileged users without the 'admin' or 'power' roles in vulnerable versions of Splunk software.
What versions are vulnerable to CVE-2024-53243?
Vulnerable versions include Splunk Enterprise below 9.3.2, 9.2.4, 9.1.7 and Splunk Secure Gateway app below 3.2.462, 3.7.18, and 3.8.5.
What impact does CVE-2024-53243 have?
CVE-2024-53243 allows low-privileged users to view alert search query responses, potentially exposing sensitive query information.