CVE-2024-45739

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Oct 17, 2024
CWE ID 200
CWE ID 532

Summary

CVE-2024-45739 is a vulnerability affecting Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6. It allows for the potential exposure of plaintext passwords for local native authentication Splunk users. This issue arises when the Splunk Enterprise AdminManager log channel is configured at the DEBUG logging level. This vulnerability poses a significant risk, as plaintext passwords can be easily accessed by unauthorized users, potentially leading to unauthorized access to the system. It is crucial for organizations using these affected versions to upgrade as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share