CVE-2017-5607
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.
- Affected products
- Splunk Enterprise, Splunk Light
- Splunk
- ≤ 6.5.1
- Fix
- Available
- CVSS 3.0
- 3.5 LOW
- EPSS
- 5.9% (93th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2017-04-10
CVE-2017-5607 at NVD
5 known exploits for CVE-2017-5607
Proof-of-concept code and exploit modules indexed by Sploitus