In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9...
Moderate severity
Unreviewed
Published
Nov 5, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Nov 4, 2022
Published to the GitHub Advisory Database
Nov 5, 2022
Last updated
Jan 30, 2023
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.
References