PT-2022-26969 · Splunk · Splunk Enterprise

Anton

+1

·

Published

2022-11-04

·

Updated

2023-06-27

·

CVE-2022-43566

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 8.2.9 Splunk Enterprise versions prior to 8.1.12 Splunk Enterprise versions prior to 9.0.2
Description The issue allows an authenticated user to run risky commands using a more privileged user’s permissions, bypassing SPL safeguards for risky commands in the Analytics Workspace. This can be achieved by tricking a victim into initiating a request within their browser, effectively phishing them. The attacker cannot exploit this issue at will, requiring the victim's interaction.
Recommendations For versions prior to 8.2.9, update to version 8.2.9 or later. For versions prior to 8.1.12, update to version 8.1.12 or later. For versions prior to 9.0.2, update to version 9.0.2 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-43566

Affected Products

Splunk Enterprise