CVE-2022-43563

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:53

Type Values Removed Values Added
Summary In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will. In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.

06 Jul 2023, 14:46

Type Values Removed Values Added
CWE CWE-20 NVD-CWE-Other

08 Nov 2022, 14:46

Type Values Removed Values Added
CPE cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
References (MISC) https://www.splunk.com/en_us/product-security/announcements/svd-2022-1103.html - (MISC) https://www.splunk.com/en_us/product-security/announcements/svd-2022-1103.html - Vendor Advisory
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Splunk
Splunk splunk
Splunk splunk Cloud Platform

04 Nov 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-04 23:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-43563

Mitre link : CVE-2022-43563

CVE.ORG link : CVE-2022-43563


JSON object : View

Products Affected

splunk

  • splunk_cloud_platform
  • splunk
CWE
NVD-CWE-Other CWE-20

Improper Input Validation