VulnerabilityModified
CVE-2023-46213
In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can result in the execution of unauthorized code in a user’s web browser.
MEDIUM 4.8EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can result in the execution of unauthorized code in a user’s web browser.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- splunk/cloud · splunk/splunk
- Source
- prodsec@splunk.com
References
- https://advisory.splunk.com/advisories/SVD-2023-1103Vendor Advisory
- https://research.splunk.com/application/1030bc63-0b37-4ac9-9ae0-9361c955a3cc/Vendor Advisory
- https://advisory.splunk.com/advisories/SVD-2023-1103Vendor Advisory
- https://research.splunk.com/application/1030bc63-0b37-4ac9-9ae0-9361c955a3cc/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.