Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wcm6-qr3c-r573

Опубликовано: 05 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.

EPSS

Процентиль: 54%
0.00313
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.

EPSS

Процентиль: 54%
0.00313
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611