QID 378039
Date Published: 2023-04-25
QID 378039: Splunk Enterprise Persistent Cross-Site Scripting (XSS) Vulnerability (SVD-2023-0202)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The vulnerability affects instances with Splunk Web enabled. It does not affect Splunk Enterprise versions below 9.0.
Affected Versions:
Splunk Enterprise 9.0 versions before 9.0.4
NOTE:
The vulnerability affects instances with Splunk Web enabled.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise.
The vulnerability may allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image.
- SVD-2023-0202 -
advisory.splunk.com/advisories/SVD-2023-0202
CVEs related to QID 378039
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0202 |
|