In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 11 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Splunk
Published:
Updated: 2025-03-11T15:02:44.575Z
Reserved: 2023-05-11T20:55:59.871Z
Link: CVE-2023-32707
Updated: 2024-08-02T15:25:37.042Z
Status : Modified
Published: 2023-06-01T17:15:10.117
Modified: 2024-11-21T08:03:53.250
Link: CVE-2023-32707
No data.
OpenCVE Enrichment
No data.
Weaknesses