CVE-2022-43570

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:26

Type Values Removed Values Added
References () https://www.splunk.com/en_us/product-security/announcements/svd-2022-1110.html - Vendor Advisory () https://www.splunk.com/en_us/product-security/announcements/svd-2022-1110.html - Vendor Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 8.8

07 Nov 2023, 03:53

Type Values Removed Values Added
Summary In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error. In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.

Information

Published : 2022-11-04 23:15

Updated : 2024-11-21 07:26


NVD link : CVE-2022-43570

Mitre link : CVE-2022-43570

CVE.ORG link : CVE-2022-43570


JSON object : View

Products Affected

splunk

  • splunk
  • splunk_cloud_platform
CWE
CWE-611

Improper Restriction of XML External Entity Reference