Vulnerability Description
Splunk 4.0.0 through 4.1.4 allows remote attackers to conduct session hijacking attacks and obtain the splunkd session key via vectors related to the SPLUNKD_SESSION_KEY parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | 4.0 |
References
- http://www.splunk.com/view/SP-CAAAFQ6PatchVendor Advisory
- http://www.splunk.com/view/SP-CAAAFQ6PatchVendor Advisory
FAQ
What is CVE-2010-3323?
CVE-2010-3323 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Splunk 4.0.0 through 4.1.4 allows remote attackers to conduct session hijacking attacks and obtain the splunkd session key via vectors related to the SPLUNKD_SESSION_KEY parameter.
How severe is CVE-2010-3323?
CVE-2010-3323 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-3323?
Check the references section above for vendor advisories and patch information. Affected products include: Splunk Splunk.