CVE-2024-36984

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.
Configurations

No configuration.

History

02 Jul 2024, 12:09

Type Values Removed Values Added
Summary
  • (es) En las versiones de Splunk Enterprise inferiores a 9.2.2, 9.1.5 y 9.0.10 en Windows, un usuario autenticado podría ejecutar una consulta especialmente manipulada que luego podría usar para serializar datos que no sean de confianza. El atacante podría utilizar la consulta para ejecutar código arbitrario.

01 Jul 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-01 17:15

Updated : 2024-10-15 18:35


NVD link : CVE-2024-36984

Mitre link : CVE-2024-36984

CVE.ORG link : CVE-2024-36984


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data