Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-23676
HistoryJan 22, 2024 - 9:15 p.m.

Code injection

2024-01-2221:15:00
PRIOn knowledge base
www.prio-n.com
4
splunk
code injection
vulnerability
version 9.0.8
version 9.1.3
low-privileged user
unauthorized index
metrics
high-privileged user
exploitation

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.0%

In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user to exploit.

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.0%

Related for PRION:CVE-2024-23676