← back
CVE-2023-22938mediumCWE-285

Permissions Validation Failure in the ‘sendemail’ REST API Endpoint in Splunk Enterprise

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N