In Splunk Enterprise versions below... CVE-2023-22934

- AV AC AU C I A
发布: 2023-02-14
修订: 2024-04-10

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser.

0%
暂无可用Exp或PoC
当前有4条受影响产品信息