The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Splunk

Published: 2022-05-06T16:35:58

Updated: 2024-08-04T00:05:51.041Z

Reserved: 2021-11-03T00:00:00

Link: CVE-2021-33845

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-06T17:15:08.577

Modified: 2022-05-17T16:56:49.960

Link: CVE-2021-33845

cve-icon Redhat

No data.