CVE-2023-22938

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-02-14 18:15

Updated : 2024-04-10 01:15


NVD link : CVE-2023-22938

Mitre link : CVE-2023-22938

CVE.ORG link : CVE-2023-22938


JSON object : View

Products Affected

splunk

  • splunk
  • splunk_cloud_platform
CWE
NVD-CWE-noinfo CWE-285

Improper Authorization