Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22940


In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not designated as safeguarded commands. The commands could potentially allow for the exposing of data to a summary index that unprivileged users could access. The vulnerability requires a higher privileged user to initiate a request within their browser, and only affects instances with Splunk Web enabled.


Published

2023-02-14T18:15:12.760

Last Modified

2024-11-21T07:45:41.120

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application splunk splunk < 8.1.13 Yes
Application splunk splunk < 8.2.10 Yes
Application splunk splunk < 9.0.4 Yes
Application splunk splunk_cloud_platform < 9.0.2209.3 Yes

References