In Splunk Enterprise versions below... CVE-2022-43570

- AV AC AU C I A
发布: 2022-11-04
修订: 2024-11-21

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.

0%
暂无可用Exp或PoC
当前有4条受影响产品信息