Description
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-46566 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error. |
References
History
Mon, 05 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Splunk
Published:
Updated: 2025-05-05T20:30:12.036Z
Reserved: 2022-10-20T18:37:09.182Z
Link: CVE-2022-43570
Updated: 2024-08-03T13:32:59.580Z
Status : Modified
Published: 2022-11-04T23:15:10.330
Modified: 2024-11-21T07:26:48.477
Link: CVE-2022-43570
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD