Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q6v-3768-8xq7

Опубликовано: 09 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

EPSS

Процентиль: 36%
0.00151
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

EPSS

Процентиль: 36%
0.00151
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770