CVE-2023-46214

Scores

EPSS

0.878high87.8%
0%20%40%60%80%100%

Percentile: 87.8%

CVSS

8.8high3.x
0246810

CVSS Score: 8.8/10

All CVSS Scores

CVSS 3.x
8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-91

Related Vulnerabilities

Vulnerable Software (2)

Type: Configuration

Vendor: *

Product: cloud

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:splunk:cloud:*:*:*:*:*:*:*:*",      "versionEndExcluding": "9.1.2308",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:splunk:...

Source: nvd

Type: Configuration

Vendor: *

Product: splunk

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:splunk:cloud:*:*:*:*:*:*:*:*",      "versionEndExcluding": "9.1.2308",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:splunk:...

Source: nvd

End of list