Impact
An SSRF flaw exists in the report notifications REST API of Splunk Secure Gateway and certain Splunk Enterprise versions. The flaw allows users who do not have admin or power roles to send system‑authenticated requests to internal Splunk services by manipulating the notification path. Attacks can alter the Search Head Cluster state or trigger a denial of service by targeting internal endpoints.
Affected Systems
Affected products are Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions prior to 3.10.9, 3.9.23, and 3.8.70. These versions include the report notifications feature without proper input validation, exposing the SSRF risk.
Risk and Exploitability
CVSS scoring indicates a medium risk with a score of 5.4, and there is no EPSS data or KEV listing, meaning the likelihood of exploitation is currently unknown. Attackers must authenticate as a standard user and craft a report notification request, exploiting an unchecked path value to trigger internal requests; once executed, it can manipulate internal services.
OpenCVE Enrichment