CVE-2017-5607: Splunk

Low severity, CVSS 3.5. EPSS: 5.9% chance of exploitation in the next 30 days.

Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.

Affected products

  • Splunk Splunk: up to and including 6.5.1; from 5.0.0, before 5.0.18 (fixed in 5.0.18); from 6.0.0, before 6.0.14 (fixed in 6.0.14); from 6.1.0, before 6.1.13 (fixed in 6.1.13); from 6.2.0, before 6.2.13.1 (fixed in 6.2.13.1); from 6.3.0, before 6.3.10 (fixed in 6.3.10); …

Published 2017-04-10. Last modified 2026-06-17.