Sploitus

CVE-2023-22934

No indexed exploits for CVE-2023-22934 yet

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass SPL safeguards for risky commands using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser.

Affected products
Splunk Enterprise
Splunk
< 8.1.13, 8.2.10, 9.0.4
Splunk Splunk Cloud Platform
< 9.0.2209.3
Fix
Available
CVSS 3.1
8.0 HIGH
EPSS
1.1% (63th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2023-02-14
CVE-2023-22934 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-22934 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-22934 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.