CVE-2022-43568 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, exploitable via a crafted JSON query parameter. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L), potentially leading to limited impact on confidentiality and integrity (C:L/I:L). There is no evidence of active exploitation, nor are public exploit modules available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1.0, < 8.1.12CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 8.2.0, < 8.2.9CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 9.0.0, < 9.0.2CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
< 9.0.2205CPE matchmatch criteria | cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.12CPE match | cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.