QID 378019
Date Published: 2023-03-13
QID 378019: Splunk Enterprise Remote Code Execution (RCE) Vulnerability (SVD-2022-1111)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
Affected Splunk Enterprise versions allow an authenticated user can execute arbitrary code through the dashboard PDF generation component.
Affected Versions:
Splunk Enterprise versions prior to 8.1.12
Splunk Enterprise versions from 8.2.0 prior to 8.2.9
Splunk Enterprise versions from 9.0.0 prior to 9.0.2
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable.
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploitation of this vulnerability may allow an authenticated user can execute arbitrary code on the target system.
- SVD-2022-1111 -
advisory.splunk.com/advisories/SVD-2022-1111
CVEs related to QID 378019
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1111 |
|