Description
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36370 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon. |
References
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2024-0702 |
|
History
No history.
Status: PUBLISHED
Assigner: Splunk
Published:
Updated: 2025-02-28T11:03:48.458Z
Reserved: 2024-05-30T16:36:20.999Z
Link: CVE-2024-36982
Updated: 2024-08-02T03:43:50.531Z
Status : Modified
Published: 2024-07-01T17:15:06.030
Modified: 2024-11-21T09:22:58.247
Link: CVE-2024-36982
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD