Denial Of Service due to Untrusted XML Tag in XML Parser within SAML Authentication
CVE-2023-32706

7.7HIGH

Key Information:

Vendor
Splunk
Vendor
CVE Published:
1 June 2023

Summary

A denial of service vulnerability exists in Splunk Enterprise, impacting versions before 9.0.5, 8.2.11, and 8.1.14. An unauthenticated attacker can exploit this flaw by sending specially-crafted messages to the XML parser during SAML authentication, resulting in the Splunk daemon becoming unresponsive. Organizations using vulnerable versions should seek updates and take immediate action to mitigate potential service disruption.

Affected Version(s)

Splunk Cloud Platform 9.0.2303 and below < 9.0.2303.100

Splunk Enterprise 8.1 < 8.1.14

Splunk Enterprise 8.2 < 8.2.11

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vikram Ashtaputre, Splunk
.