CyberRota Analysis
AI-GeneratedSplunk Enterprise versions 10.4 and below 10.4.2 are vulnerable to an unauthenticated user reloading token-signing keys via the REST API, which lacks necessary authentication checks. This could lead to unauthorized access and potential manipulation of security tokens, compromising the integrity of the system. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized actions on their Splunk deployments.
Original NVD Description
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. The vulnerability does not affect Splunk Enterprise versions below 10.4. The vulnerability is possible because the REST API does not require authentication or the change_authentication capability for the token-key reload action. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)