CyberRota Analysis
AI-GeneratedLow-privileged users in Splunk Enterprise and Splunk Cloud Platform versions prior to specified updates can exploit the `/servicesNS/-/-/storage/passwords` REST endpoint to access stored credential hashes via the `|rest` Search Processing Language command. This vulnerability could lead to unauthorized access to sensitive information, potentially compromising user accounts and system integrity. Organizations using affected versions should prioritize remediation to mitigate the risk of credential exposure.
Original NVD Description
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the `/servicesNS/-/-/storage/passwords` REST endpoint through the `|rest` Search Processing Language (SPL) command.<br><br>The exposure happens because the `|rest` SPL command returns the `encr_password` field in the results of the `/servicesNS/-/-/storage/passwords` REST endpoint.
Related CVEs
Other vulnerabilities affecting the same vendor(s)