Potential Exposure of Plaintext Passwords in Splunk Enterprise
CVE-2024-45739
4.9MEDIUM
What is CVE-2024-45739?
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at the DEBUG logging level.
Affected Version(s)
Splunk Enterprise 9.3 < 9.3.1
Splunk Enterprise 9.2 < 9.2.3
Splunk Enterprise 9.1 < 9.1.6