CyberRota Analysis
AI-GeneratedIn Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, users with the "user" role can create malicious dashboards that execute attacker-controlled Search Processing Language (SPL) on behalf of other authenticated users, potentially compromising data integrity and availability. This vulnerability arises from insufficient enforcement of app-visibility authorization boundaries in Dashboard Studio, requiring an attacker to successfully phish the targeted user. Organizations using affected versions of Splunk should prioritize remediation to mitigate the risk of unauthorized data access and system disruption.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "user" Splunk role could craft a Dashboard Studio dashboard that runs attacker-controlled Search Processing Language (SPL) for another authenticated user. The attacker-controlled SPL could access all relevant data and affect system integrity and availability. The vulnerability is possible because Dashboard Studio does not consistently enforce the expected app-visibility authorization boundary before dashboard search query options reach search dispatch. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "user" Splunk role should not be able to exploit the vulnerability at will. For more information see Create search-based visualizations with ds.search (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/dashboard-studio/10.4/use-data-sources/create-search-based-visualizations-with-ds.search) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)