← Back to browse · API

CVE-2022-43568

Severity
HIGH
CVSS
8.8
EPSS
0.42801
Risk score
50.18
CISA KEV
No
PoC
No
Published
2022-11-04
Modified
2025-05-01
First seen
2026-08-07
Aliases
EUVD-2022-46564, GHSA-5664-323M-JJ29
Products
Splunk:Splunk Enterprise 8.1 <8.1.12, Splunk:Splunk Enterprise 8.2 <8.2.9, Splunk:Splunk Enterprise 9.0 <9.0.2
Sources
euvd EUVD-2022-46564

Description

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.

References