CVE-2024-45734: Splunk
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboards. The images on the machine could be exposed by exporting the dashboard as a PDF, using the local image path in the img tag in the source extensible markup language (XML) code for the Splunk classic dashboard.
Affected products
- Splunk Splunk: from 9.1.0, before 9.1.6 (fixed in 9.1.6); from 9.2.0, before 9.2.3 (fixed in 9.2.3)
Published 2024-10-14. Last modified 2026-06-17.