In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-ID: CWE-35 CWE Name: The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize
.../...//
(doubled triple dot slash) sequences that can resolve to a location that is outside of that directory. Source: Splunk
Common Attack Pattern Enumeration and Classification (CAPEC)