CyberRota Analysis
AI-GeneratedSplunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to a Cross-Site Scripting (XSS) flaw that allows users with the "power" role to create and share malicious ui-tour objects, which can execute arbitrary JavaScript in the browsers of other authenticated users. This could lead to unauthorized data exposure and compromise system integrity based on the permissions of the affected users. Organizations using affected versions of Splunk should prioritize patching to mitigate this high-severity vulnerability.
Original NVD Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object that matches an auto-tour page name and share the object at the app level. The object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page. The JavaScript could expose all relevant data and affect system integrity within the second user permissions. The Cross-Site Scripting (XSS) vulnerability is possible because Splunk Web resolves auto-tour entries from the app namespace and uses untrusted tour content when building the tour image.
Related CVEs
Other vulnerabilities affecting the same vendor(s)