Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-10T15:00:00

Updated: 2024-08-05T15:04:15.344Z

Reserved: 2017-01-28T00:00:00

Link: CVE-2017-5607

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-04-10T15:59:00.393

Modified: 2019-03-20T19:23:45.943

Link: CVE-2017-5607

cve-icon Redhat

No data.