Description


In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at the DEBUG logging level.

Related CPE's


a

splunk

splunk

3

Weaknesses



CWE-200


CWE-532

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.9 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-10-14T15:15:12.860Z

1 year ago

Last modified

2024-10-17T11:16:36.440Z

1 year ago