Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Joshua Neubecker

#50033de 53,635
4.8CVSS total
Vulnerabilidades · 1
PT-2023-7070
4.8
2023-11-16
Splunk · Splunk Enterprise · CVE-2023-46213
**Name of the Vulnerable Software and Affected Versions** Splunk Enterprise versions prior to 9.0.7 Splunk Enterprise versions prior to 9.1.2 **Description** The issue is related to ineffective escaping in the "Show syntax Highlighted" feature, which can result in the execution of unauthorized code in a user's web browser. This can allow a remote attacker to conduct a cross-site scripting attack. **Recommendations** For versions prior to 9.0.7, update to version 9.0.7 or later. For versions prior to 9.1.2, update to version 9.1.2 or later. As a temporary workaround, consider disabling the "Show syntax Highlighted" feature until a patch is available.