CVE-2022-43570 Information
Nov 05, 2022
cve
Description
In Splunk Enterprise versions below 8.1.12 8.2.9 and 9.0.2 an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.
Reference
https://www.splunk.com/en_us/product-security/announcements/svd-2022-1110.html
Share on: