Denial Of Service due to Untrusted XML Tag in XML Parser within SAML Authentication
CVE-2023-32706
7.7HIGH
Key Information:
- Vendor
- Splunk
- Vendor
- CVE Published:
- 1 June 2023
Summary
A denial of service vulnerability exists in Splunk Enterprise, impacting versions before 9.0.5, 8.2.11, and 8.1.14. An unauthenticated attacker can exploit this flaw by sending specially-crafted messages to the XML parser during SAML authentication, resulting in the Splunk daemon becoming unresponsive. Organizations using vulnerable versions should seek updates and take immediate action to mitigate potential service disruption.
Affected Version(s)
Splunk Cloud Platform 9.0.2303 and below < 9.0.2303.100
Splunk Enterprise 8.1 < 8.1.14
Splunk Enterprise 8.2 < 8.2.11
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vikram Ashtaputre, Splunk