Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xvq-vm2p-4r2f

Опубликовано: 01 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of service (DoS) attacks.

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of service (DoS) attacks.

EPSS

Процентиль: 30%
0.00111
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-611
CWE-776

Связанные уязвимости

CVSS3: 4.6
nvd
4 месяца назад

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of service (DoS) attacks.

CVSS3: 4.6
fstec
4 месяца назад

Уязвимость веб-интерфейса Splunk Web платформы для операционного анализа Splunk Enterprise, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00111
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-611
CWE-776