Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-32714


In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.


Published

2023-06-01T17:15:10.513

Last Modified

2024-11-21T08:03:54.183

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-35
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application splunk splunk < 8.1.14 Yes
Application splunk splunk < 8.2.11 Yes
Application splunk splunk < 9.0.5 Yes
Application splunk splunk_app_for_lookup_file_editing < 4.0.1 Yes

References