CVE-2023-22941: Improperly Formatted ‘INGEST_EVAL’ Parameter Crashes Splunk Daemon
Published Feb 14, 2023
·Updated
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGESTEVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).
Other sources
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGESTEVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).
Affected Software
4 affected components
Splunk splunk>=8.1.0<8.1.13
Splunk splunk>=8.2.0<8.2.10
Splunk splunk>=9.0.0<9.0.4
Splunk Splunk Cloud Platform<9.0.2209.3
Event History
Feb 14, 2023
CVE Published
05:22 PM
Data Sourced
05:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Splunk Enterprise vulnerability?
The vulnerability ID for this Splunk Enterprise vulnerability is CVE-2023-22941.
2
What is the severity of CVE-2023-22941?
CVE-2023-22941 has a severity of 7.5 (high).
3
Which versions of Splunk Enterprise are affected by CVE-2023-22941?
Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4 are affected by CVE-2023-22941.
4
What is the impact of CVE-2023-22941?
CVE-2023-22941 can crash the Splunk daemon (splunkd).
5
How can I fix CVE-2023-22941?
To fix CVE-2023-22941, update Splunk Enterprise to version 8.1.13, 8.2.10, or 9.0.4 or later.