CVE-2023-22931
Summary
| CVE | CVE-2023-22931 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-14 18:15:00 UTC |
| Updated | 2023-11-07 04:07:00 UTC |
| Description | In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resource Description Format Site Summary (RSS) feeds without verifying permissions. This feature has been deprecated and disabled by default. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378742 Splunk Enterprise Resource Description Format Site Summary (RSS) Vulnerability (SVD-2023-0201)