CVE-2023-40593

CVSS V2 None CVSS V3 None
Description
In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.
Overview
  • CVE ID
  • CVE-2023-40593
  • Assigner
  • Splunk
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-08-30T16:19:41.308Z
  • Last Modified Date
  • 2024-04-10T00:53:04.655Z
History
Created Old Value New Value Data Type Notes
2024-06-25 02:13:53 Added to TrackCVE