Denial Of Service due to Untrusted XML Tag in XML Parser within SAML Authentication
CVE-2023-32706
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 1 June 2023
What is CVE-2023-32706?
A denial of service vulnerability exists in Splunk Enterprise, impacting versions before 9.0.5, 8.2.11, and 8.1.14. An unauthenticated attacker can exploit this flaw by sending specially-crafted messages to the XML parser during SAML authentication, resulting in the Splunk daemon becoming unresponsive. Organizations using vulnerable versions should seek updates and take immediate action to mitigate potential service disruption.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Splunk Cloud Platform 9.0.2303 and below < 9.0.2303.100
Splunk Enterprise 8.1 < 8.1.14
Splunk Enterprise 8.2 < 8.2.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved