Forum

CVE-2023-32714 - Splunk

Zitat

In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.

References
https://advisory.splunk.com/advisories/SVD-2023-0608
https://research.splunk.com/application/8ed58987-738d-4917-9e44-b8ef6ab948a6/