Impact
The vulnerability allows a non‑admin or non‑power user to retrieve query text, job identifiers, dispatch parameters, result counts, and execution metadata for other users’ search jobs via the REST API. The REST service does not perform per‑user authorization before returning job information, so the attacker can gather sensitive search job data that might reveal user intent or system usage patterns. The flaw is classified as improper authorization (CWE‑285).
Affected Systems
Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are affected. Any installation using these releases is vulnerable to the unauthorized job‑listing data exposure.
Risk and Exploitability
The reported CVSS score is 4.3, indicating medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The REST API is reachable over the network and requires only an authenticated session that does not have the admin or power role, so an attacker who has obtained or guessed valid Splunk credentials can exploit the flaw. The impact is limited to information disclosure; the CVE does not mention remote code execution or denial of service, and based on the description, no such impact is inferred.
OpenCVE Enrichment