Total vulnerabilities in the database
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the _internal
index. This exposure could happen if you configure the Splunk Enterprise REST_Calls
log channel at the DEBUG logging level.
Software | From | Fixed in |
---|---|---|
splunk / splunk | 9.1.0 | 9.1.6 |
splunk / splunk | 9.2.0 | 9.2.3 |
splunk / splunk | 9.3.0 | 9.3.0.x |