In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as “/abs/path” that can resolve to a location that is outside of that directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Splunk | Splunk | 8.2.0 (including) | 8.2.12 (excluding) |
Splunk | Splunk | 9.0.0 (including) | 9.0.6 (excluding) |
Splunk | Splunk | 9.1.0 (including) | 9.1.0 (including) |
Splunk_cloud_platform | Splunk | * | 9.0.2305.100 (including) |