In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not designated as safeguarded commands. The commands could potentially allow for the exposing of data to a summary index that unprivileged users could access. The vulnerability requires a higher privileged user to initiate a request within their browser, and only affects instances with Splunk Web enabled.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Splunk

Published: 2023-02-14T17:22:34.688Z

Updated: 2024-07-01T16:57:54.963Z

Reserved: 2023-01-10T21:39:55.584Z


Link: CVE-2023-22940

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-02-14T18:15:12.760

Modified: 2024-04-10T01:15:12.317


Link: CVE-2023-22940

JSON object: View

cve-icon Redhat Information

No data.