CVE-2023-3997

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/07/2023
Last modified:
10/12/2024

Description

Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:* 6.1.0 (excluding)
cpe:2.3:a:splunk:soar:*:*:*:*:cloud:*:*:* 6.1.0.131 (excluding)