In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8...
Low severity
Unreviewed
Published
Jun 1, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jun 1, 2023
Published to the GitHub Advisory Database
Jun 1, 2023
Last updated
Apr 4, 2024
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an attacker can use a specially crafted web URL in their browser to cause log file poisoning. The attack requires the attacker to have secure shell (SSH) access to the instance and use a terminal program that supports a certain feature set to execute the attack successfully.
References