Impact
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 an authenticated user who does not hold the \"admin\" or \"power\" roles can obtain the original JavaScript source code for the Discover Splunk Observability Cloud app through the Splunk Web interface. The flaw is caused by the presence of embedded source maps in the production bundles, which expose the code to anyone who can access the web UI. This is an information exposure vulnerability classified as CWE‑1188 and does not provide code execution, privilege escalation, or other direct system compromise.
Affected Systems
The affected product is Splunk Enterprise. All releases prior to versions 10.4.3, 10.2.7, and 10.0.10 are vulnerable; the 9.4.x series is not affected. The issue originates from the Discover Splunk Observability Cloud app bundled with these releases.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a standard user account with access to Splunk Web; the attacker can thus retrieve the app’s source code by navigating the web interface. No additional privileges or external exploits are needed. The likely attack vector is network access to the Splunk Web portal, with the threat confined to information disclosure rather than system compromise.
OpenCVE Enrichment