#VU72379 Input validation error in Splunk Enterprise - CVE-2023-22937
Published: February 20, 2023
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote user to upload files with unnecessary extensions.
The vulnerability exists due to the application allows users to upload lookup tables with unnecessary filename extensions. A remote user with the "upload_lookup_files" capability can upload files with unexpected extensions, which can have certain impact on the application.