CVE-2022-43567
Summary
| CVE | CVE-2022-43567 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-04 23:15:00 UTC |
| Updated | 2023-11-07 03:53:00 UTC |
| Description | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Splunk RCE via Splunk Secure Gateway Splunk Mobile alerts feature - Splunk Security Content |
MISC |
research.splunk.com |
|
| SVD-2022-1107 | Splunk |
MISC |
www.splunk.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378042 Splunk Enterprise Remote Code Execution (RCE) Vulnerability (SVD-2022-1107)