← Back to browse · API

CVE-2023-32714

Severity
HIGH
CVSS
8.1
EPSS
0.42824
Risk score
47.39
CISA KEV
No
PoC
No
Published
2023-06-01
Modified
2025-02-28
First seen
2026-08-07
Aliases
EUVD-2023-36941, GHSA-Q68R-7388-9J79
Products
Splunk:Splunk App for Lookup File Editing 4.0 <4.0.1
Sources
euvd EUVD-2023-36941

Description

In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.

References