Vulnerabilities (CVE)

Filtered by vendor Splunk Subscribe
Filtered by product Cloud
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46214 1 Splunk 2 Cloud, Splunk 2023-12-12 N/A 8.8 HIGH
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.