VulnerabilityModified
CVE-2022-43569
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.
MEDIUM 5.4EPSS 0.73%
Does this matter?
Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.
Description
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- splunk/splunk · splunk/splunk cloud platform
- Source
- prodsec@splunk.com
References
- https://research.splunk.com/application/062bff76-5f9c-496e-a386-cb1adcf69871/Exploit, Vendor Advisory
- https://www.splunk.com/en_us/product-security/announcements/svd-2022-1109.htmlVendor Advisory
- https://research.splunk.com/application/062bff76-5f9c-496e-a386-cb1adcf69871/Exploit, Vendor Advisory
- https://www.splunk.com/en_us/product-security/announcements/svd-2022-1109.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.