Denial Of Service due to Untrusted XML Tag in XML Parser within SAML Authentication
CVE-2023-32706

7.7HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
1 June 2023

What is CVE-2023-32706?

A denial of service vulnerability exists in Splunk Enterprise, impacting versions before 9.0.5, 8.2.11, and 8.1.14. An unauthenticated attacker can exploit this flaw by sending specially-crafted messages to the XML parser during SAML authentication, resulting in the Splunk daemon becoming unresponsive. Organizations using vulnerable versions should seek updates and take immediate action to mitigate potential service disruption.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Splunk Cloud Platform 9.0.2303 and below < 9.0.2303.100

Splunk Enterprise 8.1 < 8.1.14

Splunk Enterprise 8.2 < 8.2.11

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vikram Ashtaputre, Splunk
.