CVE-2023-46213: Splunk Cloud
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can result in the execution of unauthorized code in a user’s web browser.
Affected products
- Splunk Cloud: before 9.1.2308 (fixed in 9.1.2308)
- Splunk Splunk: from 9.0.0, before 9.0.7 (fixed in 9.0.7); from 9.1.0, before 9.1.2 (fixed in 9.1.2)
Published 2023-11-16. Last modified 2026-06-17.