CVE-2022-37438 - CERT CVE
ID CVE-2022-37438
Sažetak In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user through the drilldown component. The vulnerability requires user access to create and share dashboards using Splunk Web.
Reference
CVSS
Base: 3.5
Impact: 1.4
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
NETWORK LOW -
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Zadnje važnije ažuriranje 21-07-2023 - 19:20
Objavljeno 16-08-2022 - 21:15