CVE-2023-40595
HIGHSplunk Enterprise <8.2.12, 9.0.6, 9.1.1 - Code Injection
Title source: llmDescription
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.
Scores
CVSS v3
8.8
EPSS
0.0056
EPSS Percentile
68.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (3)
splunk/splunk
< 8.2.12
splunk/splunk
splunk/splunk_cloud_platform
< 9.0.2305.100
Timeline
Published
Aug 30, 2023
Tracked Since
Feb 18, 2026