CVE-2018-7431: Splunk

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.

Affected products

  • Splunk Splunk: before 6.6.0 (fixed in 6.6.0); from 6.0.0, before 6.0.14 (fixed in 6.0.14); from 6.1.0, before 6.1.13 (fixed in 6.1.13); from 6.2.0, before 6.2.14 (fixed in 6.2.14); from 6.3.0, before 6.3.10 (fixed in 6.3.10); from 6.4.0, before 6.4.6 (fixed in 6.4.6); …

Published 2018-10-23. Last modified 2026-06-17.