T
he XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.
References
| Link | Resource |
|---|---|
| http://www.splunk.com/view/SP-CAAAFQ6 | Patch Vendor Advisory |
| http://www.splunk.com/view/SP-CAAAFQ6 | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 01:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.splunk.com/view/SP-CAAAFQ6 - Patch, Vendor Advisory |
Information
Published : 2010-09-14 17:00
Updated : 2025-04-11 00:51
NVD link : CVE-2010-3322
Mitre link : CVE-2010-3322
CVE.ORG link : CVE-2010-3322
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference