CVE-2022-26070

When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

Information

Published : 2022-05-06 10:15

Updated : 2022-05-17 10:18


NVD link : CVE-2022-26070

Mitre link : CVE-2022-26070


JSON object : View

CWE
CWE-209

Generation of Error Message Containing Sensitive Information

Advertisement

dedicated server usa

Products Affected

splunk

  • splunk