CVE-2023-40598: Command Injection in Splunk Enterprise Using External Lookups
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-40598.
What is the severity of CVE-2023-40598?
The severity of CVE-2023-40598 is high.
Which versions of Splunk Enterprise are affected by CVE-2023-40598?
Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1 are affected by CVE-2023-40598.
How can an attacker exploit CVE-2023-40598?
An attacker can exploit CVE-2023-40598 by creating an external lookup that calls a legacy internal function and inserting code into the Splunk platform installation directory.
Is there a fix available for CVE-2023-40598?
Yes, the fix for CVE-2023-40598 is available in Splunk Enterprise versions 8.2.12, 9.0.6, and 9.1.1.