Impact
A low‑privileged Splunk user who does not have the "admin" or "power" role can send crafted requests to a REST API endpoint in the Discover Splunk Observability Cloud app. The vulnerability is caused by an inefficient regular expression used to validate input, allowing a denial of service against the endpoint. The flaw identified as CWE‑407, results in service interruption for the app and potentially the entire Splunk Enterprise instance for all users.
Affected Systems
Splunk Enterprise installations that include the Discover Splunk Observability Cloud app and run versions earlier than 10.4.3, 10.2.7, or 10.0.10 are vulnerable. Versions 9.4.x are not affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. However, because any low‑privileged user with access to the API can trigger the fault, organizations need to consider the potential for internal attackers or compromised accounts. The attack vector is likely internal network or authenticated API calls.
OpenCVE Enrichment