Vulnerabilities
Vulnerable Software
Splunk:  >> Splunk  >> 9.0.6  Security Vulnerabilities
In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-01-22
In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can result in the execution of unauthorized code in a user’s web browser.
CVSS Score
4.8
EPSS Score
0.002
Published
2023-11-16
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
CVSS Score
8.0
EPSS Score
0.881
Published
2023-11-16


Contact Us

Shodan ® - All rights reserved