Back to search
CVE-2017-5607
Published: Apr 10, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1038170
vdb-entry
x_refsource_SECTRACK
41779
exploit
x_refsource_EXPLOIT-DB
97286
vdb-entry
x_refsource_BID
20170330 Splunk Enterprise Information Theft - CVE-2017-5607
mailing-list
x_refsource_FULLDISC
20170401 Splunk Enterprise Information Theft CVE-2017-5607
mailing-list
x_refsource_BUGTRAQ
97265
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now