Splunk是美国Splunk公司的一套数据收集分析软件。该软件主要用于收集、索引和分析及其所产生的数据,包括所有IT系统和基础结构(物理、虚拟机和云)生成的数据。 Splunk Add-on Builder (AoB) 4.1.2之前版本、Splunk CloudConnect SDK 3.1.3之前版本存在信任管理问题漏洞,该漏洞源于第三方API的请求在连接失败后错误地恢复为使用HTTP进行连接。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Add-on Builder | 4.1 ~ 4.1.2 | - |
|
| Splunk | Splunk CloudConnect SDK | 3.1 ~ 3.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-22939 | 8.1 HIGH | SPL Command Safeguards Bypass via the ‘map’ SPL Command in Splunk Enterprise |
| CVE-2023-22935 | 8.1 HIGH | SPL Command Safeguards Bypass via the ‘display.page.search.patterns.sensitivity’ Search Pa |
| CVE-2023-22933 | 8.0 HIGH | Persistent Cross-Site Scripting through the ‘module’ Tag in a View in Splunk Enterprise |
| CVE-2023-22932 | 8.0 HIGH | Persistent Cross-Site Scripting through a Base64-encoded Image in a View in Splunk Enterpr |
| CVE-2023-22934 | 7.3 HIGH | SPL Command Safeguards Bypass via the ‘pivot’ SPL Command in Splunk Enterprise |
| CVE-2023-22941 | 6.5 MEDIUM | Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon |
| CVE-2023-22936 | 6.3 MEDIUM | Authenticated Blind Server Side Request Forgery via the ‘search_listener’ Search Parameter |
| CVE-2023-22940 | 6.3 MEDIUM | SPL Command Safeguards Bypass via the ‘collect’ SPL Command Aliases in Splunk Enterprise |
| CVE-2023-22942 | 5.4 MEDIUM | Cross-Site Request Forgery in the ‘ssg/kvstore_client’ REST Endpoint in Splunk Enterprise |
| CVE-2023-22938 | 4.3 MEDIUM | Permissions Validation Failure in the ‘sendemail’ REST API Endpoint in Splunk Enterprise |
| CVE-2023-22937 | 4.3 MEDIUM | Unnecessary File Extensions Allowed by Lookup Table Uploads in Splunk Enterprise |
| CVE-2023-22931 | 4.3 MEDIUM | ‘createrss’ External Search Command Overwrites Existing RSS Feeds in Splunk Enterprise |
No comments yet