CVE-2024-36991
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
- Affected products
- Splunk Enterprise
- Splunk
- < 9.0.10, 9.1.5, 9.2.2
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 13.0% (96th percentile)
- Weakness
- CWE-22, CWE-35
- NVD status
- Modified
- Published
- 2024-07-01
CVE-2024-36991 at NVD
20 known exploits for CVE-2024-36991
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-36991
CVE-2024-36991
CVE-2024-36991
CVE-2024-36991
CVE-2024-36991
CVE-2024-36991
CVE-2024-36991-Tool
CVE-2024-36991
CVE-2024-36991-Splunk
CVE-2024-36991
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk
Exploit for Path Traversal in Splunk