CVE-2023-22939: SPL Command Safeguards Bypass via the ‘map’ SPL Command in Splunk Enterprise
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.
Other sources
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘map’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher privileged user to initiate a request within their browser and only affects instances with Splunk Web enabled.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Splunk Enterprise vulnerability?
The vulnerability ID for this Splunk Enterprise vulnerability is CVE-2023-22939.
What is the severity of CVE-2023-22939?
The severity of CVE-2023-22939 is high, with a severity value of 8.8.
Which versions of Splunk Enterprise are affected by CVE-2023-22939?
Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4 are affected by CVE-2023-22939.
What does the 'map' search processing language (SPL) command allow in Splunk Enterprise?
The 'map' search processing language (SPL) command in Splunk Enterprise allows a search to bypass SPL safeguards for risky commands.
How can I fix CVE-2023-22939 vulnerability in Splunk Enterprise?
To fix the CVE-2023-22939 vulnerability in Splunk Enterprise, you need to upgrade to version 8.1.13, 8.2.10, or 9.0.4 or later.