CVE Database
/

CVE-2017-5607

Back to search

CVE-2017-5607

Published: Apr 10, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.

VendorProductVersions

n/a

n/a

affected
n/a

References

1038170
vdb-entry
x_refsource_SECTRACK
41779
exploit
x_refsource_EXPLOIT-DB
97286
vdb-entry
x_refsource_BID
97265
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now