Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62xc-vffq-mcgg

Опубликовано: 01 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.

EPSS

Процентиль: 83%
0.01891
Низкий

8 High

CVSS3

Дефекты

CWE-75
CWE-77

Связанные уязвимости

CVSS3: 8
nvd
больше 1 года назад

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.

CVSS3: 8
fstec
больше 1 года назад

Уязвимость технологии External Lookups платформы для операционного анализа Splunk Enterprise, позволяющая нарушителю повысить свои привилегии и выполнить произвольные команды

EPSS

Процентиль: 83%
0.01891
Низкий

8 High

CVSS3

Дефекты

CWE-75
CWE-77