First published: Fri Oct 10 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Splunk | <=6.0.3 | |
Splunk | =6.0.0 | |
Splunk | =6.0.1 | |
Splunk | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3147 is considered a medium-severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2014-3147, upgrade Splunk Enterprise to version 6.0.4 or later.
CVE-2014-3147 affects users of Splunk Enterprise versions before 6.0.4 with the auto-complete feature enabled.
CVE-2014-3147 enables remote authenticated users to execute arbitrary web scripts or HTML via a CSV file.
CVE-2014-3147 represents an internal threat, as it requires authenticated user access to exploit.