IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-evtx-module` is a pipeline plugin of `iris-web` that processes EVTX files through IRIS web application. During the upload of an EVTX through this pipeline, the filename is not safely handled and may cause an Arbitrary File Write. This can lead to a remote code execution (RCE) when combined with a Server Side Template Injection (SSTI). This vulnerability has been patched in version 1.0.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-05-23T12:01:39.630Z

Updated: 2024-08-02T02:42:59.989Z

Reserved: 2024-04-30T06:56:33.380Z

Link: CVE-2024-34060

cve-icon Vulnrichment

Updated: 2024-08-02T02:42:59.989Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-23T12:15:10.807

Modified: 2024-11-21T09:18:00.280

Link: CVE-2024-34060

cve-icon Redhat

No data.