SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-22938

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance.

MEDIUM 4.3EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.36% probability · 29th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
splunk/splunk · splunk/splunk cloud platform
Source
prodsec@splunk.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.