CVE-2023-22936

MEDIUM

Splunk Enterprise < 8.1.13, 8.2.10, 9.0.4 & Splunk Cloud < 9.0.2209.3 - SSRF via search_listener

Title source: llm
STIX 2.1

Description

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.

Scores

CVSS v3 6.3
EPSS 0.0017
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-918
Status published
Products (2)
splunk/splunk 8.1.0 - 8.1.13
splunk/splunk_cloud_platform < 9.0.2209.3
Published Feb 14, 2023
Tracked Since Feb 18, 2026