Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wm27-q845-m8xc

Опубликовано: 06 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can perform an unauthorized transfer of data from a search using the ‘copyresults’ command if they know the search ID (SID) of a search job that has recently run.

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can perform an unauthorized transfer of data from a search using the ‘copyresults’ command if they know the search ID (SID) of a search job that has recently run.

EPSS

Процентиль: 51%
0.00281
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.8
nvd
больше 2 лет назад

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can perform an unauthorized transfer of data from a search using the ‘copyresults’ command if they know the search ID (SID) of a search job that has recently run.

EPSS

Процентиль: 51%
0.00281
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-200