PT-2023-4030 · Splunk · Splunk Soar
Fredrik Alexandersson
·
Published
2023-07-31
·
Updated
2024-12-10
·
CVE-2023-3997
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk SOAR versions prior to 6.1.0
Description
The issue is related to the incorrect handling of log output, which can be exploited by sending a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action. A third party can exploit this to potentially execute arbitrary code.
Recommendations
For versions prior to 6.1.0, update to version 6.1.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the terminal to minimize the risk of exploitation.
Avoid using the terminal to view logs until the issue is resolved.
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Splunk Soar