logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-22934

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-22934

Description:
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser.
Last updated date:
04/10/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/23/2023
Reference url to background

https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy