CVE-2014-8303: XSS
Published Oct 16, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4 and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to event parsing.
Affected Software
10 affected components
Splunk splunk=6.0
Splunk splunk=6.0.1
Splunk splunk=6.0.2
Splunk splunk=6.0.3
Splunk splunk=6.0.4
Splunk splunk=6.0.5
Splunk splunk=6.1
Splunk splunk=6.1.1
Splunk splunk=6.1.2
Splunk splunk=6.1.3
Event History
Oct 16, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8303?
CVE-2014-8303 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-8303?
To fix CVE-2014-8303, upgrade Splunk Enterprise to version 6.1.4 or higher, or 6.0.6 or higher.
3
What types of systems are affected by CVE-2014-8303?
CVE-2014-8303 affects Splunk Enterprise versions 6.1.x before 6.1.4 and 6.0.x before 6.0.6.
4
What kind of attacks can exploit CVE-2014-8303?
CVE-2014-8303 allows remote attackers to perform cross-site scripting (XSS) attacks.
5
What are the potential impacts of CVE-2014-8303?
The potential impacts of CVE-2014-8303 include the unauthorized injection of arbitrary web scripts or HTML, leading to data theft or session hijacking.