CVE-2023-46214
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
Scoring
- Severity
- HIGH
- CVSS base score
- 8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 87.93%
- CWE
- CWE-91
- Published
- 2023-11-16
- Last modified
- 2026-03-13
Affected products
- Splunk Splunk Enterprise
- Splunk Splunk Enterprise
- Splunk Splunk Cloud
Weakness type
Related vulnerabilities
- CVE-2022-34253 — Adobe Commerce XML Injection Arbitrary code execution
- CVE-2021-36020 — Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution
- CVE-2021-36033 — Magento Commerce Widgets Module XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2021-36028 — Magento Commerce XML Injection Vulnerability Could Lead To Remote Code Execution
- CVE-2020-8479 — ABB Central Licensing System - XML External Entity Injection
- CVE-2021-21025 — Magento Commerce XML Injection Could Lead To Arbitrary Code Execution
- CVE-2021-21019 — Magento Commerce XML Injection Could Lead To Remote Code Execution
- CVE-2021-39181 — Unsafe Deserialization of User Data Using XStream