Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.2.x before 6.2.4, 6.1.x before 6.1.8, 6.0.x before 6.0.9, and 5.0.x before 5.0.13 and Splunk Light 6.2.x before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via a header.
| Software | From | Fixed in |
|---|---|---|
| splunk / splunk | 5.0.0 | 5.0.0.x |
| splunk / splunk | 6.1.2 | 6.1.2.x |
| splunk / splunk | 6.1.5 | 6.1.5.x |
| splunk / splunk | 6.1.4 | 6.1.4.x |
| splunk / splunk | 6.1.6 | 6.1.6.x |
| splunk / splunk | 6.2.3 | 6.2.3.x |
| splunk / splunk | 6.2.1 | 6.2.1.x |
| splunk / splunk | 6.0.2 | 6.0.2.x |
| splunk / splunk | 6.1.7 | 6.1.7.x |
| splunk / splunk | 6.0.1 | 6.0.1.x |
| splunk / splunk | 6.2.0 | 6.2.0.x |
| splunk / splunk | 6.0.7 | 6.0.7.x |
| splunk / splunk | 5.0.12 | 5.0.12.x |
| splunk / splunk | 6.2.2 | 6.2.2.x |
| splunk / splunk | 5.0.4 | 5.0.4.x |
| splunk / splunk | 5.0.1 | 5.0.1.x |
| splunk / splunk | 5.0.6 | 5.0.6.x |
| splunk / splunk | 5.0.3 | 5.0.3.x |
| splunk / splunk | 6.0.4 | 6.0.4.x |
| splunk / splunk | 6.0.5 | 6.0.5.x |
| splunk / splunk | 6.0.3 | 6.0.3.x |
| splunk / splunk | 5.0.8 | 5.0.8.x |
| splunk / splunk | 6.1.1 | 6.1.1.x |
| splunk / splunk | 6.0.0 | 6.0.0.x |
| splunk / splunk | 5.0.5 | 5.0.5.x |
| splunk / splunk | 5.0.11 | 5.0.11.x |
| splunk / splunk | 5.0.7 | 5.0.7.x |
| splunk / splunk | 5.0.10 | 5.0.10.x |
| splunk / splunk | 6.1.0 | 6.1.0.x |
| splunk / splunk | 5.0.2 | 5.0.2.x |
| splunk / splunk | 6.0.8 | 6.0.8.x |
| splunk / splunk | 5.0.9 | 5.0.9.x |
| splunk / splunk | 6.1.3 | 6.1.3.x |
| splunk / splunk | 6.0.6 | 6.0.6.x |