<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Splunk (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/splunk.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/splunk-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Splunk (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20239 – In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20239</guid>
    <pubDate>Wed, 20 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20239</strong></p>
  <p>In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20205 – In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20205</guid>
    <pubDate>Wed, 15 Apr 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20205</strong></p>
  <p>In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege capability `mcp_tool_admin` could view users session and authorization tokens in clear text.<br><br>The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default only the admin role…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20204 – In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20204</guid>
    <pubDate>Wed, 15 Apr 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20204</strong></p>
  <p>In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, and 9.3.2411.127, a low-privileged user that does not hold the `admin` or `power` Splunk roles could potentially perform a Remote Code Execution (RCE) by uploading a malicious file to the `$SPLUNK_HOME/var/run/splunk/ap…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20163 – In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20163</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20163</strong></p>
  <p>In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `unarchive_cmd` parameter for the `/splunkd/__upload/indexing/preview` REST endpoint.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20387 – In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20387</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20387</strong></p>
  <p>In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20386 – In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20386</guid>
    <pubDate>Wed, 03 Dec 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20386</strong></p>
  <p>In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12977 – Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to saniti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12977</guid>
    <pubDate>Mon, 24 Nov 2025 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12977</strong></p>
  <p>Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this ca…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20371 – In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20371</guid>
    <pubDate>Wed, 01 Oct 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20371</strong></p>
  <p>In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an authenticated high-privileged user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20231 – In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20231</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20231</strong></p>
  <p>In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a search using the permissions of a higher-privileged user that could lead to disclosure of sensitive information.<br><br>The vulnerability requires…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20229 – In Splunk Enterprise versions below 9.3.3, 9.2.5,  and 9.1.8, and Splunk Cloud P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20229</guid>
    <pubDate>Wed, 26 Mar 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20229</strong></p>
  <p>In Splunk Enterprise versions below 9.3.3, 9.2.5,  and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) through a file upload to the "$SPLUNK_HOME/var/run/splunk/apptemp" directory due to missing authorization checks.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53247 – In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53247</guid>
    <pubDate>Tue, 10 Dec 2024 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53247</strong></p>
  <p>In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could perform a Remote Code Execution (RCE).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45733 – In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45733</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45733</strong></p>
  <p>In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45732 – In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45732</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45732</strong></p>
  <p>In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the "nobody" Splunk user in the SplunkDeploymentServerConfig app. This could let the low-privileged user access potentially r…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45731 – In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45731</guid>
    <pubDate>Mon, 14 Oct 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45731</strong></p>
  <p>In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk Enterprise for Windows is installed on a separate drive.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36997 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36997</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36997</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a persistent cross-site scripting (XSS) exploit.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36991 – In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36991</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36991</strong></p>
  <p>In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36989 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36989</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36989</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36985 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36985</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36985</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-687</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36984 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36984</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36984</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36983 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36983</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36983</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36982 – In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36982</guid>
    <pubDate>Mon, 01 Jul 2024 17:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36982</strong></p>
  <p>In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29946 – In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29946</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29946</strong></p>
  <p>In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29945 – In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29945</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29945</strong></p>
  <p>In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either Splunk Enterprise runs in debug mode or the JsonWebToken component has been configured to log its activity at the DEBUG logging level.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46230 – In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive informat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46230</guid>
    <pubDate>Tue, 30 Jan 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46230</strong></p>
  <p>In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23678 – In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23678</guid>
    <pubDate>Mon, 22 Jan 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23678</strong></p>
  <p>In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46214 – In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46214</guid>
    <pubDate>Thu, 16 Nov 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46214</strong></p>
  <p>In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4571 – In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4571</guid>
    <pubDate>Wed, 30 Aug 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4571</strong></p>
  <p>In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Institute (ANSI) escape codes into Splunk ITSI log files that, when a vulnerable terminal application reads them, can run malicious code in the vulnerable application. This attack requires a user to use a terminal application that translates ANSI escape…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40598 – In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40598</guid>
    <pubDate>Wed, 30 Aug 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40598</strong></p>
  <p>In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40597 – In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40597</guid>
    <pubDate>Wed, 30 Aug 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40597</strong></p>
  <p>In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40596 – In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40596</guid>
    <pubDate>Wed, 30 Aug 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40596</strong></p>
  <p>In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40595 – In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40595</guid>
    <pubDate>Wed, 30 Aug 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40595</strong></p>
  <p>In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40592 – In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40592</guid>
    <pubDate>Wed, 30 Aug 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40592</strong></p>
  <p>In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scripting (XSS) on the “/app/search/table” web endpoint. Exploitation of this vulnerability can lead to the execution of arbitrary commands on the Splunk platform instance.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3997 – Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3997</guid>
    <pubDate>Mon, 31 Jul 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3997</strong></p>
  <p>Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution fr…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32714 – In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32714</guid>
    <pubDate>Thu, 01 Jun 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32714</strong></p>
  <p>In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32713 – In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32713</guid>
    <pubDate>Thu, 01 Jun 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32713</strong></p>
  <p>In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32712 – In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32712</guid>
    <pubDate>Thu, 01 Jun 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32712</strong></p>
  <p>In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application reads them, can potentially, at worst, result in possible code execution in the vulnerable application. This attack requires a user to use a terminal application that supports the tra…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32708 – In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32708</guid>
    <pubDate>Thu, 01 Jun 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32708</strong></p>
  <p>In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-113</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32707 – In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Clo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32707</guid>
    <pubDate>Thu, 01 Jun 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32707</strong></p>
  <p>In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32706 – On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32706</guid>
    <pubDate>Thu, 01 Jun 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32706</strong></p>
  <p>On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22939 – In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22939</guid>
    <pubDate>Tue, 14 Feb 2023 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22939</strong></p>
  <p>In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22935 – In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22935</guid>
    <pubDate>Tue, 14 Feb 2023 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22935</strong></p>
  <p>In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22934 – In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ searc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22934</guid>
    <pubDate>Tue, 14 Feb 2023 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22934</strong></p>
  <p>In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22933 – In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22933</guid>
    <pubDate>Tue, 14 Feb 2023 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22933</strong></p>
  <p>In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22932 – In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22932</guid>
    <pubDate>Tue, 14 Feb 2023 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22932</strong></p>
  <p>In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The vulnerability affects instances with Splunk Web enabled. It does not affect Splunk Enterprise versions below 9.0.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43572 – In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malforme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43572</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43572</strong></p>
  <p>In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer results in a blockage or denial-of-service preventing further indexing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43570 – In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43570</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43570</strong></p>
  <p>In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43569 – In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43569</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43569</strong></p>
  <p>In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43568 – In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43568</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43568</strong></p>
  <p>In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43567 – In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43567</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43567</strong></p>
  <p>In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43566 – In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43566</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43566</strong></p>
  <p>In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions to bypass  SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards  in the Analytics Workspace. The vulnerability requires the attacker to phish the victim by tricking them into initiating a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43565 – In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43565</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43565</strong></p>
  <p>In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass  SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43563 – In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex searc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43563</guid>
    <pubDate>Fri, 04 Nov 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43563</strong></p>
  <p>In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass  SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exp…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43571 – In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43571</guid>
    <pubDate>Thu, 03 Nov 2022 23:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43571</strong></p>
  <p>In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-37437 – When using Ingest Actions to configure a destination that resides on Amazon Simp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37437</guid>
    <pubDate>Tue, 16 Aug 2022 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-37437</strong></p>
  <p>When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and an Ingest Actions Destination through Splunk Web and only applies to environments that have configured TLS certificate va…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-32158 – Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32158</guid>
    <pubDate>Wed, 15 Jun 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-32158</strong></p>
  <p>Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32157 – Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32157</guid>
    <pubDate>Wed, 15 Jun 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32157</strong></p>
  <p>Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/ConfigDSDCAuthEnhancements#Configure_authentication_for_deployment_servers_and_clients…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32156 – In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32156</guid>
    <pubDate>Wed, 15 Jun 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32156</strong></p>
  <p>In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see  Configure TLS host name validation for the Splunk CLI https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_T…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32155 – In universal forwarder versions before 9.0, management services are available re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32155</guid>
    <pubDate>Wed, 15 Jun 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32155</strong></p>
  <p>In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now binds the management port to localhost preventing remote logins by default. If…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32153 – Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Clou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32153</guid>
    <pubDate>Wed, 15 Jun 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32153</strong></p>
  <p>Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and c…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32152 – Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Clou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32152</guid>
    <pubDate>Wed, 15 Jun 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32152</strong></p>
  <p>Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and c…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32151 – The httplib and urllib Python libraries that Splunk shipped with Splunk Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32151</guid>
    <pubDate>Wed, 15 Jun 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32151</strong></p>
  <p>The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203. Python 3 client libraries now verify server certificates by default and use the appropriate CA certificate stores for each lib…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27183 – The Monitoring Console app configured in Distributed mode allows for a Reflected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27183</guid>
    <pubDate>Fri, 06 May 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27183</strong></p>
  <p>The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4. The Monitoring Console app is a bundled app included in Splunk Enterprise, not for download on SplunkBase, and not installed on Splunk Cloud Platform instances. Note that the Cloud Monitoring Console is not impacted.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26889 – In Splunk Enterprise versions before 8.1.2, the uri path to load a relative reso...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26889</guid>
    <pubDate>Fri, 06 May 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26889</strong></p>
  <p>In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an attacker to potentially inject arbitrary content into the web page (e.g., HTML Injection, XSS) or bypass SPL safeguards for risky commands. The attack is browser-based. An attacker cannot exploit the attack at will and requires the attacker to initia…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-42743 – A misconfiguration in the node default path allows for local privilege escalatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-42743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-42743</guid>
    <pubDate>Fri, 06 May 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-42743</strong></p>
  <p>A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31559 – A crafted request bypasses S2S TCP Token authentication writing arbitrary events...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31559</guid>
    <pubDate>Fri, 06 May 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31559</strong></p>
  <p>A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26253 – A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26253</guid>
    <pubDate>Fri, 06 May 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26253</strong></p>
  <p>A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and does not impact or affect a DUO product or service.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3422 – The lack of validation of a key-value field in the Splunk-to-Splunk protocol res...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3422</guid>
    <pubDate>Fri, 25 Mar 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3422</strong></p>
  <p>The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-6773 – Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder whi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6773</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6773</guid>
    <pubDate>Thu, 23 Jan 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-6773</strong></p>
  <p>Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6773">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10390 – A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10390</guid>
    <pubDate>Wed, 28 Aug 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10390</strong></p>
  <p>A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5729 – Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5729</guid>
    <pubDate>Thu, 21 Mar 2019 16:01:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5729</strong></p>
  <p>Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-0029 – Juniper ATP Series Splunk credentials are logged in a file readable by authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0029</guid>
    <pubDate>Tue, 15 Jan 2019 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-0029</strong></p>
  <p>Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credentials an attacker can access the Splunk server. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-7432 – Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7432</guid>
    <pubDate>Tue, 23 Oct 2018 21:31:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-7432</strong></p>
  <p>Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote attackers to cause a denial of service via a crafted HTTP request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-7429 – Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7429</guid>
    <pubDate>Tue, 23 Oct 2018 21:31:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-7429</strong></p>
  <p>Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to cause a denial of service via a malformed HTTP request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18348 – Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18348</guid>
    <pubDate>Fri, 19 Oct 2018 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18348</strong></p>
  <p>Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-root account to modify $SPLUNK_HOME/etc/splunk-launch.conf and insert Trojan horse programs into $SPLUNK_HOME/bin, because the non-root setup instructions state that chown should be run across all of $SPLUNK_HOME to give…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-17067 – Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17067</guid>
    <pubDate>Thu, 30 Nov 2017 02:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-17067</strong></p>
  <p>Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intended access restrictions or conduct impersonation attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4017 – Salt before 2014.7.6 does not verify certificates when connecting via the aliyun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4017</guid>
    <pubDate>Fri, 25 Aug 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4017</strong></p>
  <p>Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7565 – Splunk Hadoop Connect App has a path traversal vulnerability that allows remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7565</guid>
    <pubDate>Thu, 06 Apr 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7565</strong></p>
  <p>Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-10126 – Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10126</guid>
    <pubDate>Tue, 10 Jan 2017 11:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-10126</strong></p>
  <p>Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-7394 – The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7394</guid>
    <pubDate>Thu, 07 Aug 2014 11:13:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-7394</strong></p>
  <p>The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string.  NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-6771 – Directory traversal vulnerability in the collect script in Splunk before 5.0.5 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6771</guid>
    <pubDate>Thu, 07 Aug 2014 11:13:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-6771</strong></p>
  <p>Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the file parameter.  NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7394 is for the issue in the "runshellscript echo.sh" script.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-4644 – Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4644</guid>
    <pubDate>Tue, 03 Jan 2012 11:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-4644</strong></p>
  <p>Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute management commands via an HTTP request.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3322 – The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3322</guid>
    <pubDate>Tue, 14 Sep 2010 17:00:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3322</strong></p>
  <p>The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-2502 – Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2502</guid>
    <pubDate>Mon, 28 Jun 2010 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-2502</strong></p>
  <p>Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow (1) remote attackers to read arbitrary files, aka SPL-31194; (2) remote authenticated users to modify arbitrary files, aka SPL-31063; or (3) have an unknown impact via redirects, aka SPL-31067.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2502">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
