Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow (1) remote attackers to read arbitrary files, aka SPL-31194; (2) remote authenticated users to modify arbitrary files, aka SPL-31063; or (3) have an unknown impact via redirects, aka SPL-31067. Per: http://www.splunk.com/view/SP-CAAAFGD
'Splunk recommends that customers only apply the patch as a last resort, in situations where they are unable to upgrade immediately.'
Publication date: Mon, 28 Jun 2010 23:30:00 +0000