Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32154

Опубликовано: 15 июн. 2022
Источник: nvd
CVSS3: 6.8
CVSS3: 8.1
CVSS2: 4
EPSS Низкий

Описание

Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#New_capabilities_can_limit_access_to_some_custom_and_potentially_risky_commands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Версия до 9.0 (исключая)
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
Версия до 8.2.2106 (исключая)

EPSS

Процентиль: 52%
0.00292
Низкий

6.8 Medium

CVSS3

8.1 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
CWE-77

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#New_capabilities_can_limit_access_to_some_custom_and_potentially_risky_commands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will.

EPSS

Процентиль: 52%
0.00292
Низкий

6.8 Medium

CVSS3

8.1 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20
CWE-77