CVE-2014-8380: XSS
Published Oct 21, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in a "404 Not Found" response. NOTE: this vulnerability might exist because of a CVE-2010-2429 regression.
Affected Software
1 affected component
Splunk splunk=6.1.1
Event History
Oct 21, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8380?
CVE-2014-8380 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-8380?
To fix CVE-2014-8380, it is recommended to upgrade Splunk to a version that is not affected by this vulnerability.
3
Who is affected by CVE-2014-8380?
CVE-2014-8380 affects users of Splunk version 6.1.1.
4
What type of vulnerability is CVE-2014-8380?
CVE-2014-8380 is a cross-site scripting (XSS) vulnerability.
5
What conditions must be met for CVE-2014-8380 to be exploited?
CVE-2014-8380 can be exploited when an attacker injects arbitrary web script or HTML via the HTTP Referer Header in a "404 Not Found" response.