CVE-2023-40593: Denial of Service (DoS) in Splunk Enterprise Using a Malformed SAML Request
In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the /saml/acs REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40593?
CVE-2023-40593 is a vulnerability in Splunk Enterprise versions lower than 9.0.6 and 8.2.12 that allows a malicious actor to send a malformed SAML request, causing a denial of service.
How does CVE-2023-40593 affect Splunk Enterprise?
CVE-2023-40593 affects Splunk Enterprise versions lower than 9.0.6 and 8.2.12.
What is the severity of CVE-2023-40593?
CVE-2023-40593 has a severity level of high.
How can CVE-2023-40593 be exploited?
CVE-2023-40593 can be exploited by sending a malformed SAML request to the `/saml/acs` REST endpoint in Splunk Enterprise.
Is there a fix for CVE-2023-40593?
Yes, there is a fix available for CVE-2023-40593. Upgrade to Splunk Enterprise version 9.0.6 or 8.2.12.