Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2gm-46v7-vh4c

Опубликовано: 16 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Splunk Enterprise deployment servers in versions before 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.

Splunk Enterprise deployment servers in versions before 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.

EPSS

Процентиль: 75%
0.00904
Низкий

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 9
nvd
больше 3 лет назад

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.

CVSS3: 9
fstec
больше 3 лет назад

Уязвимость серверов развертывания платформы для операционного анализа Splunk Enterprise, позволяющая нарушителю скомпрометировать конечную точку Universal Forwarder и выполнить произвольный код

EPSS

Процентиль: 75%
0.00904
Низкий

10 Critical

CVSS3