In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9...
High severity
Unreviewed
Published
Nov 5, 2022
to the GitHub Advisory Database
•
Updated Jul 6, 2023
Description
Published by the National Vulnerability Database
Nov 4, 2022
Published to the GitHub Advisory Database
Nov 5, 2022
Last updated
Jul 6, 2023
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
References