Aller au contenu

Fiche vulnérabilité

CVE-2023-40593 : faille moyenne Splunk Splunk Enterprise (CVSS 6.3)

Description

In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.

En bref

Sévérité
Moyenne (CVSS 6.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
30 août 2023
Dernière mise à jour
28 févr. 2025

Produits concernés

  • Splunk Splunk Enterprise
  • Splunk Splunk Cloud

Références

Rechercher une autre vulnérabilité dans la base CVE