In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.
https://github.com/Pocland-db/cve-pocs
https://github.com/Zin0D/CVE-2024-36991
https://github.com/milo2012/CVE-PoCs
https://github.com/Cappricio-Securities/CVE-2024-36991
https://github.com/sardine-web/CVE-2024-36991
https://github.com/th3gokul/CVE-2024-36991
https://securityaffairs.com/165204/security/splunk-enterprise-and-cloud-platform-flaws.html
https://github.com/shacojx/POC-CVE-APT
https://research.splunk.com/application/e7c2b064-524e-4d65-8002-efce808567aa