CVE Vulnerabilities

CVE-2023-40597

Absolute Path Traversal

Published: Aug 30, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.

Weakness

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as “/abs/path” that can resolve to a location that is outside of that directory.

Affected Software

Name Vendor Start Version End Version
Splunk Splunk 8.2.0 (including) 8.2.12 (excluding)
Splunk Splunk 9.0.0 (including) 9.0.6 (excluding)
Splunk Splunk 9.1.0 (including) 9.1.0 (including)
Splunk_cloud_platform Splunk * 9.0.2305.100 (including)

References