Sploitus

CVE-2023-46214

5 known exploits for CVE-2023-46214

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

Affected products
Splunk Enterprise
Splunk Cloud
< 9.1.2308
Splunk
< 9.0.7, 9.1.2
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
89.2% (100th percentile)
Weakness
CWE-91
NVD status
Modified
Published
2023-11-16
CVE-2023-46214 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2023-46214

Proof-of-concept code and exploit modules indexed by Sploitus