Impact
The flaw resides in the geostats command of Splunk Enterprise, which fails to sanitize user supplied input. An attacker who has lured a non‑admin or non‑power user into executing a crafted geostats query through a web browser can inject arbitrary Search Processing Language statements. Those injected statements run with the permissions of the second user, enabling the attacker to read any data that user can view—including stored credentials—and to alter or replace lookup files the user is permitted to modify. This results in a breach of confidentiality and integrity for all data accessible to the compromised user.
Affected Systems
Splunk Enterprise is the only impacted product. Versions earlier than 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable; all later releases contain the remediation.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS is not reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation data yet. The likely attack vector requires a phishing or social‑engineering step to get the victim to launch the malicious geostats query from Splunk Web. Because the injected SPL runs with the victim’s privileges, the attack’s impact is tied to the victim’s role and permissions. Mitigating the risk hinges on applying the vendor patch or disabling the vulnerable Web interface if patching cannot be applied immediately.
OpenCVE Enrichment