CyberRota Analysis
AI-GeneratedIn Splunk Enterprise versions prior to 10.4.1, 10.2.6, 10.0.9, and 9.4.14, users with the "power" role can inject malicious Search Processing Language (SPL) into dashboards, which is executed with the permissions of any authenticated user who exports the dashboard as a PDF. This vulnerability allows attackers to potentially access or modify sensitive data accessible to the victim user. Organizations using affected versions of Splunk Enterprise, particularly those with users in the "power" role, should prioritize patching to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store attacker-controlled Search Processing Language (SPL) in a dashboard. When another authenticated user exports the dashboard as a Portable Document Format (PDF) file, Splunk Enterprise runs the injected SPL using the permissions of that user. The injected SPL could access or modify data available to that user. The vulnerability is possible because Splunk Web does not sufficiently validate dashboard content before processing PDF exports. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "power" Splunk role should not be able to exploit the vulnerability at will. For more information see Generate PDFs of your reports and dashboards (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/9.4/report-management/generate-pdfs-of-your-reports-and-dashboards) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)