Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9mv-48mg-vv6w

Опубликовано: 01 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.

EPSS

Процентиль: 96%
0.24927
Средний

8.8 High

CVSS3

Дефекты

CWE-253
CWE-687

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.

EPSS

Процентиль: 96%
0.24927
Средний

8.8 High

CVSS3

Дефекты

CWE-253
CWE-687