mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
2.7 KiB
2.7 KiB
| 1 | splunk_risky_command | description | vulnerable_versions | CVE | other_metadata |
|---|---|---|---|---|---|
| 2 | *createrss* | createrss command overwrites existing RSS feeds without verifying permissions | 8.1.13, 8.2.10 | CVE-2023-22931 | |
| 3 | *pivot?seedSid=* | pivot command allows a search to bypass SPL safeguards for risky commands using a saved job | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22934 | |
| 4 | *|makeresults+&search_listener* | search_listener parameter in a Search allows for a Blind Server Side Request Forgery by an authenticated user | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22936 | |
| 5 | *| map search=*| * | map search processing language (SPL) command lets a search bypass SPL safeguards for risky commands | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22939 | |
| 6 | *|mcollect%20index* | collect command SPL aliases commands could potentially allow for the exposing of data to a summary index that unprivileged users could access | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22940 | |
| 7 | *|"*meventcollect*" | collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22940 | |
| 8 | *|"*summaryindex*" | collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22940 | |
| 9 | *|"*sumindex*" | collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22940 | |
| 10 | *|"*stash*" | collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22940 | |
| 11 | *| sendalert * | display.page.search.patterns.sensitivity search parameter allows a search to bypass SPL safeguards for risky commands using obfuscation | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22935 | |
| 12 | *|*runshellscript* | runshellscript searches should not be run interactively via User Interface or REST API and may be used to bypass safeguards; runshellscript may be abused to exploit legacy internal functions in external lookups leading to arbitrary code execution | <8.1.14, <8.2.12, <9.0.6, <9.1.1; <8.2.12, <9.0.6, <9.1.1 | CVE-2023-40598, CVE-2023-46214 | |
| 13 | *|*mrollup* | The “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user to exploit. | <9.0.8, <9.1.3, <9.1.2308.200 | CVE-2024-23676 |