Description
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45153 | In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code. |
References
History
No history.
Status: PUBLISHED
Assigner: Splunk
Published:
Updated: 2025-02-28T11:03:49.175Z
Reserved: 2023-08-16T22:07:52.838Z
Link: CVE-2023-40595
No data.
Status : Modified
Published: 2023-08-30T17:15:10.027
Modified: 2024-11-21T08:19:47.410
Link: CVE-2023-40595
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD