// For flags

CVE-2023-22936

Authenticated Blind Server Side Request Forgery via the ‘search_listener’ Search Parameter in Splunk Enterprise

Severity Score

6.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.

*Credits: Danylo Dmytriiev (DDV_UA)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-01-10 CVE Reserved
  • 2023-02-14 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-09-06 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Splunk
Search vendor "Splunk"
Splunk
Search vendor "Splunk" for product "Splunk"
>= 8.1.0 < 8.1.13
Search vendor "Splunk" for product "Splunk" and version " >= 8.1.0 < 8.1.13"
enterprise
Affected
Splunk
Search vendor "Splunk"
Splunk
Search vendor "Splunk" for product "Splunk"
>= 8.2.0 < 8.2.10
Search vendor "Splunk" for product "Splunk" and version " >= 8.2.0 < 8.2.10"
enterprise
Affected
Splunk
Search vendor "Splunk"
Splunk
Search vendor "Splunk" for product "Splunk"
>= 9.0.0 < 9.0.4
Search vendor "Splunk" for product "Splunk" and version " >= 9.0.0 < 9.0.4"
enterprise
Affected
Splunk
Search vendor "Splunk"
Splunk Cloud Platform
Search vendor "Splunk" for product "Splunk Cloud Platform"
< 9.0.2209.3
Search vendor "Splunk" for product "Splunk Cloud Platform" and version " < 9.0.2209.3"
-
Affected