Files
splunk-security_content/lookups/splunk_risky_command.csv
T
pyth0n1c a9dc524ad9 Make changes to lookup validation to
ensure that the structure of .csv files,
along with their quoting and number of
fields, is correct.
2023-06-27 12:07:55 -07:00

1.9 KiB

1splunk_risky_commanddescriptionvulnerable_versionsCVEother_metadata
2*createrss*createrss command overwrites existing RSS feeds without verifying permissions8.1.13, 8.2.10CVE-2023-22931
3*pivot?seedSid=*pivot command allows a search to bypass SPL safeguards for risky commands using a saved job8.1.13, 8.2.10, 9.0.4CVE-2023-22934
4*|makeresults+&search_listener*search_listener parameter in a Search allows for a Blind Server Side Request Forgery by an authenticated user8.1.13, 8.2.10, 9.0.4CVE-2023-22936
5*| map search=*| *map search processing language (SPL) command lets a search bypass SPL safeguards for risky commands8.1.13, 8.2.10, 9.0.4CVE-2023-22939
6*|mcollect%20index*collect command SPL aliases commands could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
7*|"*meventcollect*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
8*|"*summaryindex*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
9*|"*sumindex*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
10*|"*stash*"collect command SPL alias could potentially allow for the exposing of data to a summary index that unprivileged users could access8.1.13, 8.2.10, 9.0.4CVE-2023-22940
11*| sendalert *display.page.search.patterns.sensitivity search parameter allows a search to bypass SPL safeguards for risky commands using obfuscation8.1.13, 8.2.10, 9.0.4CVE-2023-22935