ZeroHour

CVE-2023-32708

CVSS 3.1
8.8 high
EPSS
<1%p53
Published
()
Modified
Description

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.

Vendors
splunk
Products
splunk, splunk cloud platform
Weakness
CWE-113, CWE-436
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.