CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
AI Score
Confidence
Low
EPSS
Percentile
47.2%
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.
[
{
"product": "Splunk Enterprise",
"vendor": "Splunk",
"versions": [
{
"version": "9.2",
"status": "affected",
"versionType": "custom",
"lessThan": "9.2.1"
},
{
"version": "9.1",
"status": "affected",
"versionType": "custom",
"lessThan": "9.1.4"
},
{
"version": "9.0",
"status": "affected",
"versionType": "custom",
"lessThan": "9.0.9"
}
]
},
{
"product": "Splunk Cloud Platform",
"vendor": "Splunk",
"versions": [
{
"version": "-",
"status": "affected",
"versionType": "custom",
"lessThan": "9.1.2312.104"
},
{
"version": "-",
"status": "affected",
"versionType": "custom",
"lessThan": "9.1.2308.205"
}
]
}
]
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
AI Score
Confidence
Low
EPSS
Percentile
47.2%