PT-2023-4030 · Splunk · Splunk Soar

Fredrik Alexandersson

·

Publicado

2023-07-31

·

Atualizado

2024-12-10

·

CVE-2023-3997

CVSS v3.1

8.6

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk SOAR versions prior to 6.1.0
Description The issue is related to the incorrect handling of log output, which can be exploited by sending a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action. A third party can exploit this to potentially execute arbitrary code.
Recommendations For versions prior to 6.1.0, update to version 6.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the terminal to minimize the risk of exploitation. Avoid using the terminal to view logs until the issue is resolved.

Correção

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04328
CVE-2023-3997

Produtos afetados

Splunk Soar