vendor:
                    Splunk
                by:
                    Parsa rezaie khiabanloo
                4.1
                        CVSS
                    MEDIUM
                    Information Disclosure
                    200
                        CWE
                    Product Name: Splunk
                    Affected Version From:  9.0.0
                    Affected Version To:  9.0.4
                    Patch Exists: NO
                    Related CWE: 
                    CPE:  splunk:9.0.4
                    Platforms Tested:  Windows
                    2023
                    Splunk 9.0.4 – Information Disclosure
Splunk version 9.0.4 is vulnerable to information disclosure where an attacker can append /__raw/services/server/info/server-info?output_mode=json to a query to access sensitive data like license keys. This can lead to unauthorized access to critical information.
Mitigation:
					To mitigate this vulnerability, restrict access to the affected endpoint and ensure proper input validation to prevent unauthorized queries.