8.8
CVSSv3

CVE-2023-32708

Published: 01/06/2023 Updated: 10/04/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

splunk splunk cloud platform

splunk splunk