CVE-2023-22936: Authenticated Blind Server Side Request Forgery via the ‘search_listener’ Search Parameter in Splunk Enterprise
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘searchlistener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22936?
CVE-2023-22936 is a vulnerability in Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4 that allows for a blind server-side request forgery (SSRF) by an authenticated user.
How does CVE-2023-22936 affect Splunk Enterprise?
CVE-2023-22936 affects Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4.
What is the severity of CVE-2023-22936?
The severity of CVE-2023-22936 is medium with a severity value of 6.3.
How can I fix CVE-2023-22936?
To fix CVE-2023-22936, update your Splunk Enterprise version to 8.1.13, 8.2.10, or 9.0.4.
Where can I find more information about CVE-2023-22936?
You can find more information about CVE-2023-22936 on the Splunk advisory page: [https://advisory.splunk.com/advisories/SVD-2023-0206](https://advisory.splunk.com/advisories/SVD-2023-0206) and the Splunk research page: [https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd](https://research.splunk.com/application/ee69374a-d27e-4136-adac-956a96ff60fd)