In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
No PoCs from references.
- https://github.com/0xMarcio/cve
- https://github.com/12442RF/POC
- https://github.com/20142995/nuclei-templates
- https://github.com/Cappricio-Securities/CVE-2024-36991
- https://github.com/DMW11525708/wiki
- https://github.com/GhostTroops/TOP
- https://github.com/J1ezds/Vulnerability-Wiki-page
- https://github.com/Lern0n/Lernon-POC
- https://github.com/Mr-xn/CVE-2024-36991
- https://github.com/MrR0b0t19/SplunkVuln
- https://github.com/Ostorlab/KEV
- https://github.com/TcchSquad/CVE-2024-36991-Tool
- https://github.com/TheStingR/CVE-2024-36991-Tool
- https://github.com/Threekiii/Awesome-POC
- https://github.com/Threekiii/CVE
- https://github.com/Zin0D/CVE-2024-36991
- https://github.com/adysec/POC
- https://github.com/bigb0x/CVE-2024-36991
- https://github.com/eeeeeeeeee-code/POC
- https://github.com/fcoomans/HTB-machines
- https://github.com/gunzf0x/CVE-2024-36991
- https://github.com/jaytiwari05/CVE-2024-36991
- https://github.com/laoa1573/wy876
- https://github.com/lineeralgebra/My-Favorite-Boxes
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/oLy0/Vulnerability
- https://github.com/onewinner/POCS
- https://github.com/plzheheplztrying/cve_monitor
- https://github.com/sardine-web/CVE-2024-36991
- https://github.com/tanjiti/sec_profile
- https://github.com/th3gokul/CVE-2024-36991
- https://github.com/xploitnik/CVE-2024-36991-modified