CVE-2022-43571
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
- Affected products
- Splunk Enterprise
- Splunk
- < 8.1.12, 8.2.9, 9.0.2
- Splunk Splunk Cloud Platform
- < 9.0.2209
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 13.8% (96th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2022-11-03
CVE-2022-43571 at NVD
5 known exploits for CVE-2022-43571
Proof-of-concept code and exploit modules indexed by Sploitus