CyberRota Analysis
AI-GeneratedIn Splunk AI Toolkit versions prior to 6.0.1, users lacking "admin" or "power" roles can exploit a flaw in the REST API to delete another user's experiment history without authorization. This vulnerability poses a risk of unauthorized data manipulation, potentially leading to loss of critical experiment information. Organizations using affected versions should prioritize patching to mitigate the risk of data integrity issues.
Original NVD Description
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)