CyberRota Analysis
AI-GeneratedSplunk AI Toolkit versions prior to 6.0.0 are vulnerable to arbitrary code execution due to improper deserialization of untrusted sparse matrix data by a model codec, which allows users with the "power" role to exploit this flaw. The impact of this vulnerability is significant, as it could lead to unauthorized access and control over the Splunk server. Organizations using affected versions of the Splunk AI Toolkit should prioritize patching to mitigate potential security risks.
Original NVD Description
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Troubleshoot the Splunk Machine Learning Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/machine-learning-toolkit-user-guide/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)