CyberRota Analysis
AI-GeneratedIn Splunk Enterprise and Splunk Secure Gateway versions prior to specified updates, non-admin users can access sensitive Spacebridge asymmetric private keys through an insecure REST API, potentially compromising stored private-key material. This vulnerability primarily affects organizations using these versions, especially those that have upgraded from older deployments without completing the private-key migration. Organizations should prioritize remediation to protect their key material and prevent unauthorized access.
Original NVD Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key material stored in the app collection, through the Splunk Secure Gateway App Key Value Store Representational State Transfer (REST) API. The vulnerability is possible on instances upgraded from older Splunk Secure Gateway deployments when the private-key migration remains incomplete, leaving key material in a collection with an insecure default access control list.
Related CVEs
Other vulnerabilities affecting the same vendor(s)