Files
splunk-security_content/lookups/splunk_risky_command_20231003.csv
pyth0n1c 732aec3f95 Delete detection and migrate
logic and documentation to risky
command lookup file. Update macro
to point to new risky command csv.
Fiox some opservables.
2023-09-28 14:51:28 -07:00

2.2 KiB

1splunk_risky_commanddescriptionvulnerable_versionsCVEother_metadata
2*createrss*createrss command overwrites existing RSS feeds without verifying permissions8.1.13, 8.2.10CVE-2023-22931
3*pivot?seedSid=*pivot command allows a search to bypass SPL safeguards for risky commands using a saved job8.1.13, 8.2.10, 9.0.4CVE-2023-22934
4*|makeresults+&search_listener*search_listener parameter in a Search allows for a Blind Server Side Request Forgery by an authenticated user8.1.13, 8.2.10, 9.0.4CVE-2023-22936
5*| map search=*| *map search processing language (SPL) command lets a search bypass SPL safeguards for risky commands8.1.13, 8.2.10, 9.0.4CVE-2023-22939
6*|mcollect%20index*collect command SPL aliases commands could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
7*|"*meventcollect*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
8*|"*summaryindex*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
9*|"*sumindex*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
10*|"*stash*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
11*| sendalert *display.page.search.patterns.sensitivity search parameter allows a search to bypass SPL safeguards for risky commands using obfuscation8.1.13, 8.2.10, 9.0.4CVE-2023-22935
12*| *runshellscript* ""*runshellscript searches should not be run interactively via User Interface or REST API and may be used to bypass safeguards; runshellscript may be abused to exploit legacy internal functions in external lookups leading to arbitrary code execution<8.1.14, <8.2.12, <9.0.6, <9.1.1; <8.2.12, <9.0.6, <9.1.1CVE-2023-40598