CyberRota Analysis
AI-GeneratedIn Splunk Enterprise versions prior to 10.4.2 and 10.2.6, users lacking "admin" or "power" roles can exploit a broken object level authorization flaw to delete SPL2 modules belonging to other users via the data management orchestrator interface. This vulnerability could lead to unauthorized data loss and disruption of services for affected users. Organizations using these versions should prioritize patching to mitigate potential risks associated with unauthorized access and data management.
Original NVD Description
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language version 2 (SPL2) modules belonging to other users through the data management orchestrator interface. The vulnerability does not affect Splunk Enterprise versions below 10.2. The broken object level authorization is possible because the data management orchestrator does not verify that the requesting user owns the target resources before it deletes the modules. For more information see Manage SPL2-based apps (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/meet-splunk-apps/manage-spl2-based-apps) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)