vulnerability

Splunk CVE-2022-43571: Remote Code Execution through dashboard PDF generation component in Splunk Enterprise

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Nov 2, 2022
Added
Apr 7, 2025
Modified
Apr 22, 2025

Description

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.

Solution

splunk-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.