CVE-2023-3997
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.08%
- CWE
- CWE-117
- Published
- 2023-07-31
- Last modified
- 2026-03-13
Affected products
- Splunk Splunk SOAR (On-premises)
- Splunk Splunk SOAR (Cloud)
Weakness type
Related vulnerabilities
- CVE-2026-25548 — InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
- CVE-2024-47083 — Power Platform Terraform Provider has Improper Masking of Secrets in Logs
- CVE-2024-29022 — Session Hijacking via XSS attack in header and session grid in Xibo CMS
- CVE-2023-32712 — Unauthenticated Log Injection in Splunk Enterprise
- CVE-2024-25047 — IBM Cognos Analytics log injection
- CVE-2023-4571 — Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
- CVE-2026-81696 — openssl_encrypt before 1.4.9 Terminal Injection via info Command