CVE-2014-3147: XSS
Published Oct 10, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.
Affected Software
4 affected components
Splunk splunk<=6.0.3
Splunk splunk=6.0.0
Splunk splunk=6.0.1
Splunk splunk=6.0.2
Event History
Oct 10, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3147?
CVE-2014-3147 is considered a medium-severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2014-3147?
To fix CVE-2014-3147, upgrade Splunk Enterprise to version 6.0.4 or later.
3
Who is affected by CVE-2014-3147?
CVE-2014-3147 affects users of Splunk Enterprise versions before 6.0.4 with the auto-complete feature enabled.
4
What kind of attack does CVE-2014-3147 enable?
CVE-2014-3147 enables remote authenticated users to execute arbitrary web scripts or HTML via a CSV file.
5
Is CVE-2014-3147 an internal or external threat?
CVE-2014-3147 represents an internal threat, as it requires authenticated user access to exploit.