CVE-2023-22932: Splunk
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The vulnerability affects instances with Splunk Web enabled. It does not affect Splunk Enterprise versions below 9.0.
Affected products
- Splunk Splunk: from 9.0.0, before 9.0.4 (fixed in 9.0.4)
- Splunk Splunk Cloud Platform: before 9.0.2209.3 (fixed in 9.0.2209.3)
Published 2023-02-14. Last modified 2026-06-17.