QID 378022
Date Published: 2023-03-29
QID 378022: Splunk Enterprise Internal Path Disclosure Vulnerabilities (SVD-2022-0507)
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path.
Affected Versions:
Versions below 8.1
QID Detection Logic(Authenticated)
It checks for vulnerable version of Splunk Enterprise .
Successful exploitation of this vulnerability could lead to a Internal Path Disclosure.
Solution
Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2022-0507
Vendor References
- SVD-2022-0507 -
advisory.splunk.com/advisories/SVD-2022-0507
CVEs related to QID 378022
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0507 |
|