ZeroHour

CVE-2023-32714

CVSS 3.1
8.1 high
EPSS
43%p99
Published
()
Modified
Description

In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.

Vendors
splunk
Products
splunk, splunk app for lookup file editing
Weakness
CWE-35, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.