CyberRota Analysis
AI-GeneratedIn Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, users with the high-privilege list_search_head_clustering capability can exploit control endpoints to alter the cluster state, potentially leading to a denial of service. This vulnerability arises from insufficient validation of HTTP request types for state-changing operations. Organizations using affected versions, particularly those with users holding elevated privileges, should prioritize patching to mitigate the risk of service disruption.
Original NVD Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints and change cluster state, which could allow for a denial of service. The vulnerability is possible because the Search Head Cluster member control endpoints do not require a state-changing Hypertext Transfer Protocol (HTTP) request type before they apply read-only authorization.
Related CVEs
Other vulnerabilities affecting the same vendor(s)