Exploitation Attempt Of CVE-2023-46214 Using Public POC Code
Description
Detects exploitation attempt of CVE-2023-46214, a remote code execution (RCE) in Splunk Enterprise through insecure XML parsing using known public proof of concept code
Query · sigma
selection_method_and_response: cs-method: POST sc-status: - 200 - 302 selection_uri_upload: cs-uri-stem|contains: /splunkd/__upload/indexing/preview cs-uri-query|contains|all: - NO_BINARY_CHECK=1 - input.path=shell.xsl selection_uri_search: cs-uri-stem|contains|all: - /api/search/jobs - /results cs-uri-query|contains|all: - /opt/splunk/var/run/splunk/dispatch/ - /shell.xsl condition: selection_method_and_response and 1 of selection_uri_*
Known false positives
- Unlikely