CyberRota Analysis
AI-GeneratedSplunk Enterprise Security versions prior to 8.6.1 are vulnerable to an injection flaw that allows users with the mc_investigation_read capability to manipulate Search Processing Language (SPL) through Analyst Queue search filters. This could lead to unauthorized access to sensitive data and compromise system integrity, as the search filter handling lacks proper validation. Organizations using affected versions should prioritize patching to mitigate potential data breaches and maintain security compliance.
Original NVD Description
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the scheduled searches that run for that user. The vulnerability is possible because the Analyst Queue search filter handling does not validate filter field names before the fields are included in SPL searches. For more information see Users and roles for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/install/8.4/installation/users-and-roles-for-splunk-enterprise-security), Manage analyst workflows using the analyst queue in Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.4/mission-control/manage-analyst-workflows-using-the-analyst-queue-in-splunk-enterprise-security), and Overview of Mission Control in Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.5/mission-control/overview-of-mission-control-in-splunk-enterprise-security) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)