CVE-2023-32714: Path Traversal in Splunk App for Lookup File Editing
Published Jun 1, 2023
·Updated
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.
Affected Software
4 affected components
Splunk splunk>=8.1.0<8.1.14
Splunk splunk>=8.2.0<8.2.11
Splunk splunk>=9.0.0<9.0.5
Splunk Splunk App for Lookup File Editing<4.0.1
Event History
Jun 1, 2023
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
DescriptionSeverityWeakness
Data Sourced
05:15 PM
Description
Frequently Asked Questions
1
What is CVE-2023-32714?
CVE-2023-32714 is a path traversal vulnerability in the Splunk App for Lookup File Editing.
2
What is the severity of CVE-2023-32714?
CVE-2023-32714 has a severity rating of 8.1, which is considered high.
3
Which versions of Splunk App for Lookup File Editing are affected by CVE-2023-32714?
Splunk App for Lookup File Editing versions below 4.0.1 are affected by CVE-2023-32714.
4
How can a low-privileged user exploit CVE-2023-32714?
A low-privileged user can exploit CVE-2023-32714 by sending a specially crafted web request that triggers a path traversal exploit.
5
What can an attacker do with CVE-2023-32714?
An attacker can use CVE-2023-32714 to read and write to restricted areas of the Splunk installation directory.