In Splunk Enterprise versions below... CVE-2023-22939

- AV AC AU C I A
发布: 2023-02-14
修订: 2024-04-10

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.

0%
暂无可用Exp或PoC
当前有4条受影响产品信息