PT-2023-7397 · Splunk · Splunk App For Lookup File Editing

CVE-2023-32715

·

Publicado

2023-06-01

·

Atualizado

2024-04-10

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Splunk App for Lookup File Editing versions prior to 4.0.1
Description The issue allows a user to insert potentially malicious JavaScript code into the app, causing it to run on the user's machine. This does not require the app itself to contain malicious code. Exploitation requires the attacker to trick the victim into initiating a request within their browser and needs additional user interaction. The attacker cannot exploit this issue at will. It is related to a lack of protection for the web page structure, which could allow a remote attacker to conduct a cross-site scripting attack.
Recommendations For versions prior to 4.0.1, update to version 4.0.1 or later to resolve the issue. As a temporary workaround, consider restricting user interaction with the app to minimize the risk of exploitation. Avoid using the app for inserting JavaScript code until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08434
CVE-2023-32715

Produtos afetados

Splunk App For Lookup File Editing