Files
splunk-security_content/lookups/splunk_risky_command.csv
pyth0n1c e8d1b150b4 Update appinspect to do more complete inspection,
using precert and doing all inspection not
just cloud inspection, because it will catch
more issues with the package.  Also, update
some lookups that had commas in fields.
Finally, remove a column from one lookup
and the corresponding detection.
2023-05-04 16:06:04 -07:00

1.8 KiB

1splunk_risky_commanddescriptionvulnerable_versionsCVE
2*createrss*createrss command overwrites existing RSS feeds without verifying permissions8.1.13, 8.2.10CVE-2023-22931
3*pivot?seedSid=*pivot command allows a search to bypass SPL safeguards for risky commands using a saved job8.1.13, 8.2.10, 9.0.4CVE-2023-22934
4*|makeresults+&search_listener*search_listener parameter in a Search allows for a Blind Server Side Request Forgery by an authenticated user8.1.13, 8.2.10, 9.0.4CVE-2023-22936
5*| map search=*| *map search processing language (SPL) command lets a search bypass SPL safeguards for risky commands8.1.13, 8.2.10, 9.0.4CVE-2023-22939
6*| sendalert *display.page.search.patterns.sensitivity search parameter allows a search to bypass SPL safeguards for risky commands using obfuscation8.1.13, 8.2.10, 9.0.4CVE-2023-22935