Security Advisory

CVE-2022-43561

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-11-03 22:06:41
Last updated 2025-04-25 19:10:23
Assigner Splunk
CVSS score 6.4
State PUBLISHED

Description

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.