Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.
2023-07-31T17:15:10.110
2024-12-10T18:15:25.547
Modified
CVSSv3.1: 8.6 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | splunk | soar | < 6.1.0 | Yes |
Application | splunk | soar | < 6.1.0.131 | Yes |