Security Advisory

CVE-2022-43562

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-11-04 22:19:11
Last updated 2025-05-05 20:37:25
Assigner Splunk
CVSS score 3.0
State PUBLISHED

Description

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.