Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwwq-v92j-38xr

Опубликовано: 16 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

EPSS

Процентиль: 99%
0.87931
Высокий

8 High

CVSS3

Дефекты

CWE-91

Связанные уязвимости

CVSS3: 8
nvd
около 2 лет назад

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

CVSS3: 8
fstec
около 2 лет назад

Уязвимость платформы для операционного анализа Splunk Enterprise, связанная с ошибками в обработке XML-запросов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.87931
Высокий

8 High

CVSS3

Дефекты

CWE-91