On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, an unauthorized user can access the {{/services/indexing/preview}} REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://advisory.splunk.com/advisories/SVD-2023-0612 | vendor advisory |
https://research.splunk.com/application/bbe26f95-1655-471d-8abd-3d32fafa86f8/ | vendor advisory |