CVE-2024-29946
Estado: ModificadaAlta (8.1)—
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.77%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-77
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-29946",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-29946",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-03-30T04:00:57.413620Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "prodsec@splunk.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "prodsec@splunk.com",
"affectedData": [
{
"vendor": "Splunk",
"product": "Splunk Enterprise",
"versions": [
{
"status": "affected",
"version": "9.2",
"lessThan": "9.2.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.1",
"lessThan": "9.1.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.0",
"lessThan": "9.0.9",
"versionType": "custom"
}
]
},
{
"vendor": "Splunk",
"product": "Splunk Cloud Platform",
"versions": [
{
"status": "affected",
"version": "-",
"lessThan": "9.1.2312.104",
"versionType": "custom"
},
{
"status": "affected",
"version": "-",
"lessThan": "9.1.2308.205",
"versionType": "custom"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*"
],
"vendor": "splunk",
"product": "splunk",
"versions": [
{
"status": "affected",
"version": "9.2",
"lessThan": "9.2.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.1",
"lessThan": "9.1.4",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.0",
"lessThan": "9.0.9",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:splunk:cloud:*:*:*:*:*:*:*:*"
],
"vendor": "splunk",
"product": "cloud",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "9.1.2312.104",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"lessThan": "9.1.2308.205",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-03-27T17:15:54.273",
"references": [
{
"url": "https://advisory.splunk.com/advisories/SVD-2024-0302",
"tags": [
"Vendor Advisory"
],
"source": "prodsec@splunk.com"
},
{
"url": "https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/",
"tags": [
"Vendor Advisory"
],
"source": "prodsec@splunk.com"
},
{
"url": "https://advisory.splunk.com/advisories/SVD-2024-0302",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "prodsec@splunk.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser."
},
{
"lang": "es",
"value": "En las versiones de Splunk Enterprise inferiores a 9.2.1, 9.1.4 y 9.0.9, el Centro de ejemplos de paneles de la aplicación Splunk Dashboard Studio carece de protección para comandos SPL riesgosos. Esto podría permitir a los atacantes eludir las salvaguardas de SPL para comandos riesgosos en el Hub. La vulnerabilidad requeriría que el atacante realice phishing a la víctima engañándola para que inicie una solicitud dentro de su navegador."
}
],
"lastModified": "2026-06-17T07:23:24.873",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A74446C-DAAB-4030-99BF-3DFA48BAA885",
"versionEndExcluding": "9.0.9",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6672A8C0-21AA-4534-B789-E1BCC7DCFEF8",
"versionEndExcluding": "9.1.4",
"versionStartIncluding": "9.1.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39900641-B270-4F6C-8E33-CB3124B0E914",
"versionEndExcluding": "9.2.1",
"versionStartIncluding": "9.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "prodsec@splunk.com"
}