CVE-2023-22931Improper Authorization in Cloud Platform

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 66.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateJul 6

Description

In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resource Description Format Site Summary (RSS) feeds without verifying permissions. This feature has been deprecated and disabled by default.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5splunk/splunk_enterprise8.18.1.13+1
NVDsplunk/splunk8.1.08.1.13+1
CVEListV5splunk/splunk_cloud_platform-8.2.2203

🔴Vulnerability Details

2
GHSA
GHSA-7g93-5vcp-frv5: In Splunk Enterprise versions below 82023-07-06
CVEList
‘createrss’ External Search Command Overwrites Existing RSS Feeds in Splunk Enterprise2023-02-14
CVE-2023-22931 — Improper Authorization in Splunk | cvebase