CyberRota Analysis
AI-GeneratedSplunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to unauthorized access, allowing unauthenticated users to read JavaScript files located outside the designated static directory. This exposure could lead to information disclosure, potentially revealing sensitive data or application logic. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized data access.
Original NVD Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability is possible because Splunk Web does not restrict static file requests to the configured static directory.
Related CVEs
Other vulnerabilities affecting the same vendor(s)