
Proof-of-concept exploit for CVE-2022-43571, demonstrating remote code execution in Splunk via crafted sparklines to justify security updates.
CVE-2022-43571 Splunk RCE – my personal journey to color your life Only because I got the statement from my IT, there are no reasons for a SPLUNK update, I analyzed this vulnerability CVE-2022-43571 to prove the opposite for a remote code execution. Here is my exploit.
If I had found this vulnerability, I would like to name this „colorful sparklines“ ….. ;-)
@SPLUNK you should not name the vulnerability nor address any details in your code. It was a fast pointer into right direction ;-) /splunk/lib/python3.7/site-packages/splunk/pdf/pdfgen_utils.py