CVE-2023-32717: Role-based Access Control (RBAC) Bypass on '/services/indexing/preview' REST Endpoint Can Overwrite Search Results
On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, an unauthorized user can access the {{/services/indexing/preview}} REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-32717.
What is the severity of CVE-2023-32717?
The severity of CVE-2023-32717 is medium with a CVSS score of 4.3.
Which versions of Splunk Enterprise are affected by CVE-2023-32717?
Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14 are affected by CVE-2023-32717.
Which versions of Splunk Cloud Platform are affected by CVE-2023-32717?
Splunk Cloud Platform versions below 9.0.2303.100 are affected by CVE-2023-32717.
How can an unauthorized user exploit CVE-2023-32717?
An unauthorized user can access the /services/indexing/preview REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job.
Is there a fix for CVE-2023-32717?
Yes, upgrading to Splunk Enterprise version 9.0.5, 8.2.11, or 8.1.14, or Splunk Cloud Platform version 9.0.2303.100 will fix CVE-2023-32717.