Loading HuntDB...

GHSA-p7r4-77g3-vcrx

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘pivot’ search processing language (SPL) command lets a search bypass [SPL safeguards for risky commands](https://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards) using a saved search job. The vulnerability requires an authenticated user to craft the saved job and a higher privileged user to initiate a request within their browser. The vulnerability affects instances with Splunk Web enabled.

Related CVEs

Key Information

GHSA ID
GHSA-p7r4-77g3-vcrx
Published
July 6, 2023 7:24 PM
Last Modified
August 2, 2024 12:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 16, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.