Логотип exploitDog
bind:CVE-2023-22938
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-22938

Количество 2

Количество 2

nvd логотип

CVE-2023-22938

почти 3 года назад

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f44g-3vj9-vwv9

больше 2 лет назад

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-22938

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-f44g-3vj9-vwv9

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу