In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
2022-11-03T23:15:21.987
2024-11-21T07:26:48.610
Modified
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | splunk | splunk | < 8.1.12 | Yes |
| Application | splunk | splunk | < 8.2.9 | Yes |
| Application | splunk | splunk | < 9.0.2 | Yes |
| Application | splunk | splunk_cloud_platform | < 9.0.2209 | Yes |