CVE-2022-32157
Summary
| CVE | CVE-2022-32157 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-15 17:15:00 UTC |
| Updated | 2022-06-24 00:51:00 UTC |
| Description | Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/ConfigDSDCAuthEnhancements#Configure_authentication_for_deployment_servers_and_clients). Once enabled, deployment servers can manage only Universal Forwarder versions 9.0 and higher. Though the vulnerability does not directly affect Universal Forwarders, remediation requires updating all Universal Forwarders that the deployment server manages to version 9.0 or higher prior to enabling the remediation. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SVD-2022-0607 | Splunk | CONFIRM | www.splunk.com | |
| Splunk Process Injection Forwarder Bundle Downloads - Splunk Security Content | CONFIRM | research.splunk.com | |
| Configure authentication for deployment servers and clients - Splunk Documentation | CONFIRM | docs.splunk.com | |
| Security updates - Splunk Documentation | CONFIRM | docs.splunk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Nadim Taha at Splunk
There are currently no legacy QID mappings associated with this CVE.