mappy.py in Splunk Web in Splunk 4.2.x prior to 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
splunk splunk 4.2.4 |
||
splunk splunk 4.2.2 |
||
splunk splunk 4.2.3 |
||
splunk splunk 4.2 |
||
splunk splunk 4.2.1 |