CVE-2023-32713: Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32713?
CVE-2023-32713 is a vulnerability in the Splunk App for Stream that allows a low-privileged user to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user.
How severe is CVE-2023-32713?
CVE-2023-32713 is considered critical with a severity score of 9.9 out of 10.
How can a low-privileged user exploit CVE-2023-32713?
A low-privileged user can exploit CVE-2023-32713 by using a vulnerability in the streamfwd process within the Splunk App for Stream.
Which versions of the Splunk App for Stream are affected by CVE-2023-32713?
Versions of the Splunk App for Stream below 8.1.1 are affected by CVE-2023-32713.
Is there a fix for CVE-2023-32713?
Yes, upgrading to version 8.1.1 or above of the Splunk App for Stream fixes CVE-2023-32713.