Vulnerability Description
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | <= 6.5.1 |
Related Weaknesses (CWE)
References
- http://hyp3rlinx.altervista.org/advisories/SPLUNK-ENTERPRISE-INFORMATION-THEFT.tExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2017/Mar/89ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/540346/100/0/threadedExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/97265Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/97286Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038170Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41779/ExploitThird Party AdvisoryVDB Entry
- https://www.splunk.com/view/SP-CAAAPZ3#InformationLeakageviaJavaScriptCVE2017560Vendor Advisory
- http://hyp3rlinx.altervista.org/advisories/SPLUNK-ENTERPRISE-INFORMATION-THEFT.tExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2017/Mar/89ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/540346/100/0/threadedExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/97265Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/97286Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038170Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41779/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-5607?
CVE-2017-5607 is a vulnerability with a CVSS score of 3.5 (LOW). Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 as...
How severe is CVE-2017-5607?
CVE-2017-5607 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5607?
Check the references section above for vendor advisories and patch information. Affected products include: Splunk Splunk.