mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
e8d1b150b4
using precert and doing all inspection not just cloud inspection, because it will catch more issues with the package. Also, update some lookups that had commas in fields. Finally, remove a column from one lookup and the corresponding detection.
1.8 KiB
1.8 KiB
| 1 | splunk_risky_command | description | vulnerable_versions | CVE |
|---|---|---|---|---|
| 2 | *createrss* | createrss command overwrites existing RSS feeds without verifying permissions | 8.1.13, 8.2.10 | CVE-2023-22931 |
| 3 | *pivot?seedSid=* | pivot command allows a search to bypass SPL safeguards for risky commands using a saved job | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22934 |
| 4 | *|makeresults+&search_listener* | search_listener parameter in a Search allows for a Blind Server Side Request Forgery by an authenticated user | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22936 |
| 5 | *| map search=*| * | map search processing language (SPL) command lets a search bypass SPL safeguards for risky commands | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22939 |
| 6 | *| sendalert * | display.page.search.patterns.sensitivity search parameter allows a search to bypass SPL safeguards for risky commands using obfuscation | 8.1.13, 8.2.10, 9.0.4 | CVE-2023-22935 |