Security Advisory
CVE-2010-3322
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.