Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-786j-r97c-7r7v

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.

EPSS

Процентиль: 31%
0.00119
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.3
nvd
почти 3 года назад

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.

EPSS

Процентиль: 31%
0.00119
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-918