CVE-2023-22935: SPL Command Safeguards Bypass via the ‘display.page.search.patterns.sensitivity’ Search Parameter in Splunk Enterprise
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.
Other sources
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22935?
CVE-2023-22935 is a vulnerability in Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4 that allows a search to bypass SPL safeguards for risky commands.
What is the severity of CVE-2023-22935?
The severity of CVE-2023-22935 is high with a CVSS score of 8.8.
How does CVE-2023-22935 affect Splunk Enterprise?
CVE-2023-22935 affects Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4.
How can I fix CVE-2023-22935?
To fix CVE-2023-22935, update Splunk Enterprise to version 8.1.13, 8.2.10, or 9.0.4.
What is the CWE of CVE-2023-22935?
The CWE of CVE-2023-22935 is CWE-77: Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection').