CVE Vulnerabilities

CVE-2023-22941

Uncaught Exception

Published: Feb 14, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

NameVendorStart VersionEnd Version
SplunkSplunk8.1.0 (including)8.1.13 (excluding)
SplunkSplunk8.2.0 (including)8.2.10 (excluding)
SplunkSplunk9.0.0 (including)9.0.4 (excluding)
Splunk_cloud_platformSplunk*9.0.2209.3 (excluding)

References