Описание
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.
Уязвимые конфигурации
Конфигурация 1Версия от 8.1.0 (включая) до 8.1.12 (исключая)Версия от 8.2.0 (включая) до 8.2.9 (исключая)Версия от 9.0.0 (включая) до 9.0.2 (исключая)Версия до 9.0.2208 (исключая)
Одно из
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00304
Низкий
3 Low
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-20
CWE-74
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.
EPSS
Процентиль: 53%
0.00304
Низкий
3 Low
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-20
CWE-74