CVE-2023-22940

MEDIUM

Splunk Enterprise < 8.1.13, 8.2.10, 9.0.4 - Unauthorized Data Exposure via SPL Command Aliases

Title source: llm
STIX 2.1

Description

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not designated as safeguarded commands. The commands could potentially allow for the exposing of data to a summary index that unprivileged users could access. The vulnerability requires a higher privileged user to initiate a request within their browser, and only affects instances with Splunk Web enabled.

Scores

CVSS v3 6.3
EPSS 0.0034
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

Details

CWE
CWE-20
Status published
Products (2)
splunk/splunk 8.1.0 - 8.1.13
splunk/splunk_cloud_platform < 9.0.2209.3
Published Feb 14, 2023
Tracked Since Feb 18, 2026