Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54hj-cc7x-rq4c

Опубликовано: 01 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

EPSS

Процентиль: 87%
0.03457
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

EPSS

Процентиль: 87%
0.03457
Низкий

8.8 High

CVSS3

Дефекты

CWE-502