CVE-2023-22938

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

History

23 Feb 2023, 15:35

Type Values Removed Values Added
References (MISC) https://advisory.splunk.com/advisories/SVD-2023-0208 - (MISC) https://advisory.splunk.com/advisories/SVD-2023-0208 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
First Time Splunk splunk
Splunk splunk Cloud Platform
Splunk
CPE cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

14 Feb 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-14 18:15

Updated : 2024-04-10 01:15


NVD link : CVE-2023-22938

Mitre link : CVE-2023-22938

CVE.ORG link : CVE-2023-22938


JSON object : View

Products Affected

splunk

  • splunk_cloud_platform
  • splunk
CWE
NVD-CWE-noinfo CWE-285

Improper Authorization