首页 时政热点 科技头条 智能AI 安全攻防 数码硬件 开发者生态 汽车 游戏 社会热点 开源推荐 医疗健康 归档 标签 关于

Splunk Enterprise 的严重缺陷可让攻击者在未经身份验证的情况下运行代码

摘要

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution。

Splunk security Enterprise could unauthenticated
2026-06-13 1 阅读 约1分钟阅读 info@thehackernews.com (The Hacker News)
分享:
字号:
Splunk 已发布安全更新,以解决 Splunk Enterprise 中的一个关键安全漏洞,该漏洞可被利用来进行未经身份验证的文件操作,甚至远程代码执行。该漏洞的编号为 CVE-2026-20253,CVSS 评分系统的评分为 9.8。 “在低于 10.2.4 和 10.0.7 的 Splunk Enterprise 版本中,未经身份验证的用户可以创建或截断任意
这篇文章对您有帮助吗?

订阅66必读

每日精选科技资讯,直达你的邮箱