Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ghx-2vfx-7347

Опубликовано: 30 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.

In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.

EPSS

Процентиль: 30%
0.0011
Низкий

8.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.5
nvd
больше 2 лет назад

In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.

CVSS3: 8.5
fstec
больше 2 лет назад

Уязвимость веб-интерфейса Splunk Web платформы для операционного анализа Splunk Enterprise, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 30%
0.0011
Низкий

8.5 High

CVSS3

Дефекты

CWE-306