Lucene search

K
nvd[email protected]NVD:CVE-2023-46214
HistoryNov 16, 2023 - 9:15 p.m.

CVE-2023-46214

2023-11-1621:15:08
CWE-91
web.nvd.nist.gov
1
splunk enterprise
xslt
vulnerability
remote code execution

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.363 Low

EPSS

Percentile

97.2%

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

Affected configurations

NVD
Node
splunkcloudRange<9.1.2308
OR
splunksplunkRange9.0.09.0.7enterprise
OR
splunksplunkRange9.1.09.1.2enterprise

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.363 Low

EPSS

Percentile

97.2%