Critical Path Traversal Flaw in Splunk Enterprise Puts Windows Systems at Risk

Red | Vulnerability Report

A high-severity vulnerability identified in Splunk, CVE-2024-36991, has been discovered. This vulnerability is associated with Path Traversal on the “/modules/messaging/” endpoint in Splunk Enterprise on Windows. It allows attackers to traverse the file system and access files or directories outside the restricted directory. A proof of concept for this vulnerability is publicly available on GitHub.

Reduce real exposure. Not just vulnerability volume.