CVE-2023-22937: Unnecessary File Extensions Allowed by Lookup Table Uploads in Splunk Enterprise
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup tables with unnecessary filename extensions. Lookup table file extensions may now be one of the following only: .csv, .csv.gz, .kmz, .kml, .mmdb, or .mmdb.gzl.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Splunk vulnerability?
The vulnerability ID for this Splunk vulnerability is CVE-2023-22937.
What versions of Splunk Enterprise are affected by this vulnerability?
Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4 are affected by this vulnerability.
What is the severity level of CVE-2023-22937?
The severity level of CVE-2023-22937 is medium, with a severity value of 4.3.
What is the impact of this vulnerability?
This vulnerability allows a user to upload lookup tables with unnecessary filename extensions in Splunk Enterprise, potentially leading to unauthorized access or execution of arbitrary code.
How can I fix CVE-2023-22937?
To fix CVE-2023-22937, upgrade Splunk Enterprise to version 8.1.13, 8.2.10, or 9.0.4, which restricts the lookup table file extensions to .csv, .csv.gz, .kmz, .kml, .mmdb, or .mmdb.gzl.