Splunk是美国Splunk公司的一套数据收集分析软件。该软件主要用于收集、索引和分析及其所产生的数据,包括所有IT系统和基础结构(物理、虚拟机和云)生成的数据。 Splunk Enterprise存在安全漏洞,该漏洞源于由于对HTTP请求来源的验证不充分。远程攻击者可以诱使受害者访问特制网页,并代表受害者在易受攻击的网站上执行任意操作,并使用搜索命令绕过SPL保护措施以获取风险命令,执行跨站请求伪造攻击。以下产品和版本受到影响:Splunk Enterprise 8.2.0至8.2.8版本、8.1.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 8.1 ~ 8.1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-43570 | 8.8 HIGH | XML External Entity Injection through a custom View in Splunk Enterprise |
| CVE-2022-43568 | 8.8 HIGH | Reflected Cross-Site Scripting via the radio template in Splunk Enterprise |
| CVE-2022-43567 | 8.8 HIGH | Remote Code Execution via the Splunk Secure Gateway application Mobile Alerts feature |
| CVE-2022-43565 | 8.1 HIGH | Risky command safeguards bypass via ‘tstats command JSON in Splunk Enterprise |
| CVE-2022-43569 | 8.0 HIGH | Persistent Cross-Site Scripting via a Data Model object name in Splunk Enterprise |
| CVE-2022-43572 | 7.5 HIGH | Indexing blockage via malformed data sent through S2S or HEC protocols in Splunk Enterpris |
| CVE-2022-43566 | 7.3 HIGH | Risky command safeguards bypass via Search ID query in Analytics Workspace in Splunk Enter |
| CVE-2022-43564 | 4.9 MEDIUM | Denial of Service in Splunk Enterprise through search macros |
| CVE-2022-43562 | 3.0 LOW | Host Header Injection in Splunk Enterprise |
No comments yet