CVE-2023-40595: Remote Code Execution via Serialized Session Payload
Published Aug 30, 2023
·Updated
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.
Affected Software
4 affected components
Splunk splunk>=8.2.0<8.2.12
Splunk splunk>=9.0.0<9.0.6
Splunk splunk=9.1.0
Splunk Splunk Cloud Platform<=9.0.2305.100
Event History
Aug 30, 2023
CVE Published
04:19 PM
Data Sourced
04:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-40595?
The severity of CVE-2023-40595 is critical.
2
Which versions of Splunk Enterprise are affected by CVE-2023-40595?
Versions lower than 8.2.12, 9.0.6, and 9.1.1 of Splunk Enterprise are affected by CVE-2023-40595.
3
How can an attacker exploit CVE-2023-40595?
An attacker can exploit CVE-2023-40595 by executing a specially crafted query to serialize untrusted data and execute arbitrary code.
4
Is the Splunk Cloud Platform affected by CVE-2023-40595?
Yes, the Splunk Cloud Platform is affected by CVE-2023-40595.
5
How can I fix CVE-2023-40595?
To fix CVE-2023-40595, upgrade to Splunk Enterprise versions 8.2.12, 9.0.6, or 9.1.1, depending on your current version.