PT-2023-3015 · Splunk · Splunk Enterprise+1

Try_To_Hack

·

Publicado

2023-06-01

·

Atualizado

2024-04-10

·

CVE-2023-32707

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 9.0.5 Splunk Enterprise versions prior to 8.2.11 Splunk Enterprise versions prior to 8.1.14 Splunk Cloud Platform versions prior to 9.0.2303.100
Description A low-privileged user with the edit user capability can escalate their privileges to that of the admin user by providing specially crafted web requests. The issue is related to authorization procedure weaknesses in the authorize.conf configuration file. This can allow a remote attacker to elevate their privileges.
Recommendations For Splunk Enterprise versions prior to 9.0.5, update to version 9.0.5 or later. For Splunk Enterprise versions prior to 8.2.11, update to version 8.2.11 or later. For Splunk Enterprise versions prior to 8.1.14, update to version 8.1.14 or later. For Splunk Cloud Platform versions prior to 9.0.2303.100, update to version 9.0.2303.100 or later. As a temporary workaround, consider restricting the edit user capability to prevent privilege escalation until a patch is applied.

Exploit

Correção

Improper Authorization

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03078
CVE-2023-32707

Produtos afetados

Splunk Cloud Platform
Splunk Enterprise