Impact
This vulnerability allows a non‑admin or non‑power user in Splunk Enterprise or Splunk Secure Gateway to read security Assertion Markup Language setup and instance settings via REST API endpoints that do not enforce proper authorization. The flaw results in disclosure of sensitive configuration information, potentially exposing details that could assist in further attacks. The weakness is a classic information disclosure, identified as CWE‑200.
Affected Systems
Affected are Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70. The vulnerability impacts both products when the Splunk Secure Gateway app is installed.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need only to authenticate with a non‑admin, non‑power role and make a REST API call over the network to obtain the exposed configuration data. Although there is no EPSS data, the exposure of SAML settings could enable attackers to craft further exploits. The impact is limited to information disclosure, but the specific data revealed may assist in planning additional attacks.
OpenCVE Enrichment