Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrpm-3gh9-qhp6

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.

EPSS

Процентиль: 35%
0.00142
Низкий

8.8 High

CVSS3

Дефекты

CWE-20
CWE-77

Связанные уязвимости

CVSS3: 8.1
nvd
почти 3 года назад

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.

EPSS

Процентиль: 35%
0.00142
Низкий

8.8 High

CVSS3

Дефекты

CWE-20
CWE-77