In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Splunk

Published: 2023-02-14T17:22:38.050Z

Updated: 2024-10-30T15:06:12.523Z

Reserved: 2023-01-10T21:39:55.583Z

Link: CVE-2023-22936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-02-14T18:15:12.460

Modified: 2024-11-21T07:45:40.567

Link: CVE-2023-22936

cve-icon Redhat

No data.