ZeroHour

CVE-2023-40595

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
Description

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.

Vendors
splunk
Products
splunk, splunk cloud platform
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.