In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could cause data exfiltration through classic dashboards by redirecting a victim to an external site using a protocol-relative URL in a drill-down link.<br><br>The vulnerability exists because the URL classifier in classic dashboards only recognizes `http://` and `https://` schemes when checking for external URLs. Protocol-relative URLs such as `//attacker.com` bypass this check entirely, and Splunk Web does not show the external-navigation warning dialog to the victim.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.3.0, < 9.3.13CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 9.4.0, < 9.4.12CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 10.0.0, < 10.0.7CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 10.2.0, < 10.2.4CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 9.3.2411, < 9.3.2411.132CPE matchmatch criteria | cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.