漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise
Vulnerability Description
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability into running arbitrary Search Processing Language (SPL) searches on their behalf as `splunk-system-user`, allowing for access to stored credentials and indexed data.<br><br>The vulnerability is possible because Deployment Server endpoints in Splunk Web do not validate Cross-Site Request Forgery (CSRF) tokens on GET requests, and caller-supplied input is not correctly neutralized before it is placed into an SPL search.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Splunk Enterprise 跨站请求伪造漏洞
Vulnerability Description
Splunk Splunk Enterprise是美国Splunk公司的日志分析系统。 Splunk Enterprise存在跨站请求伪造漏洞,该漏洞源于Splunk Web中的部署服务器端点未验证GET请求上的跨站请求伪造令牌,且调用者提供的输入未被正确清理即放入SPL搜索,可能导致攻击者诱使用户运行任意SPL搜索,从而访问存储的凭据和索引数据。以下版本受到影响:10.4.1之前版本、10.2.5之前版本、10.0.8之前版本、9.4.13之前版本、10.5.2605.0之前版本、10.4.2604.7
CVSS Information
N/A
Vulnerability Type
N/A