Improper Output Neutralization for Logs in Splunk Enterprise - CVE-2023-32712
Published: June 5, 2023
Splunk Enterprise
Splunk Inc.
Description
The vulnerability allows a remote attacker to alter log files.
The vulnerability exists due to improper input validation. A remote attacker can use a specially crafted web URL in their browser to cause log file injection, in which the attack inserts American National Standards Institute (ANSI) escape codes into specific files using a terminal program that supports those escape codes.
The attack requires a terminal program that supports the translation of ANSI escape codes and requires additional user interaction to successfully execute.