CVE-2023-40592: Reflected Cross-site Scripting (XSS) on "/app/search/table" web endpoint
In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scripting (XSS) on the “/app/search/table” web endpoint. Exploitation of this vulnerability can lead to the execution of arbitrary commands on the Splunk platform instance.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2023-40592.
What is the severity of CVE-2023-40592?
The severity of CVE-2023-40592 is high.
How does CVE-2023-40592 impact Splunk Enterprise?
CVE-2023-40592 allows an attacker to perform reflected cross-site scripting (XSS) on the "/app/search/table" web endpoint of Splunk Enterprise, potentially leading to the execution of arbitrary commands on the Splunk system.
Which versions of Splunk Enterprise are affected by CVE-2023-40592?
Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12 are affected by CVE-2023-40592.
How can I fix CVE-2023-40592 in Splunk Enterprise?
To fix CVE-2023-40592, you should upgrade Splunk Enterprise to version 9.1.1 if on version 9.x, 9.0.6 if on version 9.0.x, or 8.2.12 if on version 8.2.x.