CVE-2023-32707: ‘edit_user’ Capability Privilege Escalation
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edituser’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Splunk Enterprise vulnerability?
The vulnerability ID for this Splunk Enterprise vulnerability is CVE-2023-32707.
What is the severity of CVE-2023-32707?
The severity of CVE-2023-32707 is high with a severity value of 8.8.
Which versions of Splunk Enterprise are affected by CVE-2023-32707?
Versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14 are affected by CVE-2023-32707.
How can a low-privileged user escalate their privileges to that of the admin user in Splunk Enterprise?
A low-privileged user can escalate their privileges to that of the admin user in Splunk Enterprise by providing specially crafted web requests.
Are Splunk Cloud Platform versions affected by CVE-2023-32707?
Yes, Splunk Cloud Platform versions below 9.0.2303.100 are affected by CVE-2023-32707.