First published: Thu Oct 16 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4 and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to event parsing.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Splunk | =6.0 | |
Splunk | =6.0.1 | |
Splunk | =6.0.2 | |
Splunk | =6.0.3 | |
Splunk | =6.0.4 | |
Splunk | =6.0.5 | |
Splunk | =6.1 | |
Splunk | =6.1.1 | |
Splunk | =6.1.2 | |
Splunk | =6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8303 is classified as a medium severity vulnerability.
To fix CVE-2014-8303, upgrade Splunk Enterprise to version 6.1.4 or higher, or 6.0.6 or higher.
CVE-2014-8303 affects Splunk Enterprise versions 6.1.x before 6.1.4 and 6.0.x before 6.0.6.
CVE-2014-8303 allows remote attackers to perform cross-site scripting (XSS) attacks.
The potential impacts of CVE-2014-8303 include the unauthorized injection of arbitrary web scripts or HTML, leading to data theft or session hijacking.