CVE-2022-26889

Description

In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an attacker to potentially inject arbitrary content into the web page (e.g., HTML Injection, XSS) or bypass SPL safeguards for risky commands. The attack is browser-based. An attacker cannot exploit the attack at will and requires the attacker to initiate a request within the victims browser (e.g., phishing).

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.141

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-26889 are fixed in Splunk Enterprise 8 (8.1.2)Windows
Vulnerabilities CVE-2022-26889 are fixed in Splunk Enterprise 8 (x64) (8.1.2)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-325532Splunk Enterprise 8 (8.2.7)
PATCH-332589Splunk Enterprise 8 (x64) (8.2.12)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234