CVE Vulnerabilities

CVE-2023-40594

Published: Aug 30, 2023 | Modified: Apr 10, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the printf SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.

Affected Software

Name Vendor Start Version End Version
Splunk Splunk 8.2.0 (including) 8.2.12 (excluding)
Splunk Splunk 9.0.0 (including) 9.0.6 (excluding)
Splunk Splunk 9.1.0 (including) 9.1.0 (including)
Splunk_cloud_platform Splunk * 9.0.2305.100 (including)

References