ZeroHour

CVE-2023-40597

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
Description

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.

Vendors
splunk
Products
splunk, splunk cloud platform
Weakness
CWE-36, CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.