CVE-2017-5607
LOW 3.5EPSS 5.9%
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.
- CVSS v3.0
- 3.5 LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N - CVSS v2.0
- 3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N - EPSS
- 5.85% chance of exploitation in the next 30 days, 93th percentile
- Published
- 2017-04-10
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- http://hyp3rlinx.altervista.org/advisories/SPLUNK-ENTERPRISE-INFORMATION-THEFT.txt
- http://seclists.org/fulldisclosure/2017/Mar/89