Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-22934
HistoryFeb 14, 2023 - 6:15 p.m.

Design/Logic Flaw

2023-02-1418:15:00
PRIOn knowledge base
www.prio-n.com
4
splunk enterprise
logic flaw
security vulnerability
search language
saved search job
authenticated user
higher privileged user

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.7%

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser.

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.7%

Related for PRION:CVE-2023-22934