The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.
References
| Link | Resource |
|---|---|
| http://www.splunk.com/view/SP-CAAAFQ6 | Patch Vendor Advisory |
| http://www.splunk.com/view/SP-CAAAFQ6 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2010-09-14 17:00
Updated : 2025-04-11 00:51
NVD link : CVE-2010-3322
Mitre link : CVE-2010-3322
CVE.ORG link : CVE-2010-3322
JSON object : View
Products Affected
splunk
- splunk
CWE
CWE-611
Improper Restriction of XML External Entity Reference
