logo

Splunk Addresses Critical Vulnerabilities in Enterprise and Cloud Platforms

ID: 38072acf-fd9b-561e-9248-f473369c2f87

STIX ID: report--38072acf-fd9b-561e-9248-f473369c2f87

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2024-07-05

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Splunk released updates addressing 16 vulnerabilities — most prominently CVE-2024-36985 (RCE via External Lookup using copybuckets.py in splunk_archiver) and CVE-2024-36984 (authenticated code execution via serialized session payload). Affected Splunk Enterprise versions precede 9.0.10, 9.1.5, and 9.2.2; Splunk recommends prompt upgrades or temporarily disabling the splunk_archiver app as mitigation, and reports no observed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.