CVE-2023-22940
Summary
| CVE | CVE-2023-22940 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-14 18:15:00 UTC |
| Updated | 2023-12-21 01:28:00 UTC |
| Description | In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not designated as safeguarded commands. The commands could potentially allow for the exposing of data to a summary index that unprivileged users could access. The vulnerability requires a higher privileged user to initiate a request within their browser, and only affects instances with Splunk Web enabled. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Splunk | Splunk | All | All | All | All |
| Application | Splunk | Splunk Cloud Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SVD-2023-0210 | Splunk Vulnerability Disclosure | MISC | advisory.splunk.com | |
| Page Not Found - Splunk Security Content | MISC | research.splunk.com | |
| research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd | MISC | research.splunk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378009 Splunk Enterprise Multiple Vulnerabilities (SVD-2023-0212,SVD-2023-0210,SVD-2023-0209,SVD-2023-0205,SVD-2023-0204,SVD-2023-0203)