In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’.
References
Link | Resource |
---|---|
https://advisory.splunk.com/advisories/SVD-2023-0203 | Vendor Advisory |
https://research.splunk.com/application/9ac2bfea-a234-4a18-9d37-6d747e85c2e4 | Exploit Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Splunk
Published: 2023-02-14T17:22:40.081Z
Updated: 2024-07-01T16:57:50.944Z
Reserved: 2023-01-10T21:39:55.583Z
Link: CVE-2023-22933
JSON object: View
NVD Information
Status : Modified
Published: 2023-02-14T18:15:12.220
Modified: 2024-04-10T01:15:11.057
Link: CVE-2023-22933
JSON object: View
Redhat Information
No data.
CWE