mirror of
https://github.com/gobysec/GobyVuls.git
synced 2025-06-20 09:50:49 +00:00
Create Splunk_Enterprise_XSLT_Command_Execute_Vulnerability.md
This commit is contained in:
parent
865777ad01
commit
98f2d80fd1
12
Splunk_Enterprise_XSLT_Command_Execute_Vulnerability.md
Normal file
12
Splunk_Enterprise_XSLT_Command_Execute_Vulnerability.md
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
## Splunk Enterprise XSLT Command Execute Vulnerability (CVE-2023-46214)
|
||||||
|
|
||||||
|
| **Vulnerability** | Splunk Enterprise XSLT Command Execute Vulnerability (CVE-2023-46214) |
|
||||||
|
| :----: | :-----|
|
||||||
|
| **Chinese name** | Splunk Enterprise XSLT 命令执行漏洞(CVE-2023-46214) |
|
||||||
|
| **CVSS core** | 8.0 |
|
||||||
|
| **FOFA Query** (click to view the results directly)| [app="splunk-Enterprise"](https://en.fofa.info/result?qbase64=Ym9keT0iX19zcGx1bmtkX3BhcnRpYWxzX18iICB8fCAoaGVhZGVyPSJTZXQtQ29va2llOiBzcGx1bmt3ZWJfdWlkPSIgJiYgYm9keT0iZW50ZXJwcmlzZSIp)|
|
||||||
|
| **Number of assets affected** | 134567 |
|
||||||
|
| **Description** | Splunk Enterprise is a data collection and analysis software developed by Splunk Corporation in the United States. This software is mainly used for collecting, indexing, and analyzing the data it generates, including data generated by all IT systems and infrastructure (physical, virtual machines, and cloud).Splunk Enterprise has a command execution vulnerability that does not securely clean up user provided Extensible Stylesheet Language Transformations (XSLTs). Attackers can exploit this vulnerability to upload malicious XSLTs and remotely execute commands on Splunk Enterprise instances. |
|
||||||
|
| **Impact** | Splunk Enterprise has a command execution vulnerability that does not securely clean up user provided Extensible Stylesheet Language Transformations (XSLTs). Attackers can exploit this vulnerability to upload malicious XSLTs and remotely execute commands on Splunk Enterprise instances. |
|
||||||
|
|
||||||
|

|
Loading…
x
Reference in New Issue
Block a user