Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v6j-9rv8-9mrh

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.

EPSS

Процентиль: 36%
0.00151
Низкий

7.2 High

CVSS3

Дефекты

CWE-113
CWE-436

Связанные уязвимости

CVSS3: 7.2
nvd
больше 2 лет назад

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.

EPSS

Процентиль: 36%
0.00151
Низкий

7.2 High

CVSS3

Дефекты

CWE-113
CWE-436