Splunk是美国Splunk公司的一套数据收集分析软件。该软件主要用于收集、索引和分析及其所产生的数据,包括所有IT系统和基础结构(物理、虚拟机和云)生成的数据。 Splunk Enterprise存在安全漏洞,该漏洞源于可以通过数据模型对象名称触发跨站脚本,可能导致在网站上下文中执行任意JavaScript代码。以下产品和版本受到影响:Splunk Enterprise 9.0.0至9.0.1版本、8.2.0至8.2.8版本、8.1.0至8.1.11版本、8.0.0至8.0.10版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Enterprise | 8.1 ~ 8.1.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-43570 | 8.8 HIGH | XML External Entity Injection through a custom View in Splunk Enterprise |
| CVE-2022-43568 | 8.8 HIGH | Reflected Cross-Site Scripting via the radio template in Splunk Enterprise |
| CVE-2022-43567 | 8.8 HIGH | Remote Code Execution via the Splunk Secure Gateway application Mobile Alerts feature |
| CVE-2022-43565 | 8.1 HIGH | Risky command safeguards bypass via ‘tstats command JSON in Splunk Enterprise |
| CVE-2022-43563 | 8.1 HIGH | Risky command safeguards bypass via rex search command field names in Splunk Enterprise |
| CVE-2022-43572 | 7.5 HIGH | Indexing blockage via malformed data sent through S2S or HEC protocols in Splunk Enterpris |
| CVE-2022-43566 | 7.3 HIGH | Risky command safeguards bypass via Search ID query in Analytics Workspace in Splunk Enter |
| CVE-2022-43564 | 4.9 MEDIUM | Denial of Service in Splunk Enterprise through search macros |
| CVE-2022-43562 | 3.0 LOW | Host Header Injection in Splunk Enterprise |
No comments yet