Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cuong Dong

Researcher fromSplunk
#15275of 53,633
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2022-26966
8.8
2022-11-04
Splunk · Splunk Enterprise · CVE-2022-43563
**Name of the Vulnerable Software and Affected Versions** Splunk Enterprise versions prior to 8.2.9 Splunk Enterprise versions prior to 8.1.12 **Description** The issue arises from how the rex search command handles field names, allowing an attacker to bypass SPL safeguards for risky commands. This requires the attacker to phish the victim into initiating a request within their browser, meaning the attacker cannot exploit the issue at will. **Recommendations** For versions prior to 8.2.9, update to version 8.2.9 or later. For versions prior to 8.1.12, update to version 8.1.12 or later.
PT-2022-26968
8.8
2022-11-04
Splunk · Splunk Enterprise · CVE-2022-43565
**Name of the Vulnerable Software and Affected Versions** Splunk Enterprise versions prior to 8.2.9 Splunk Enterprise versions prior to 8.1.12 **Description** The issue arises from how the `tstats` command handles Javascript Object Notation (JSON), allowing an attacker to bypass SPL safeguards for risky commands. This requires the attacker to trick the victim into initiating a request within their browser through phishing. **Recommendations** For versions prior to 8.2.9, update to version 8.2.9 or later. For versions prior to 8.1.12, update to version 8.1.12 or later.