QID 378020
Date Published: 2023-03-13
QID 378020: Splunk Enterprise Multiple Security Vulnerabilities (SVD-2022-1109, SVD-2022-1110)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2022-43569: Affected Splunk Enterprise versions allows authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.
CVE-2022-43570: Affected Splunk Enterprise versions allows an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.
Affected Versions:
Splunk Enterprise versions prior to 8.1.12
Splunk Enterprise versions from 8.2.0 prior to 8.2.9
Splunk Enterprise versions from 9.0.0 prior to 9.0.2
NOTE:
The vulnerability affects instances with Splunk Web enabled only.
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/web.conf" or "/etc/system/local/web.conf".
Successful exploitation of these vulnerabilities may allow an authenticated attacker either inject and execute arbitrary JavaScript code or perform XXE injection on the target system.
Workaround:
Disable Splunk Web and restricting upload lookup files.
- SVD-2022-1109 -
advisory.splunk.com/advisories/SVD-2022-1109 - SVD-2022-1110 -
advisory.splunk.com/advisories/SVD-2022-1110
CVEs related to QID 378020
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1109 |
|
||
| SVD-2022-1110 |
|