QID 378023
Date Published: 2023-03-27
QID 378023: Splunk Enterprise Local Privilege Escalation Vulnerability (SVD-2023-0207)
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup tables with unnecessary filename extensions. Lookup table file extensions may now be one of the following only: .csv, .csv.gz, .kmz, .kml, .mmdb, or .mmdb.gzl.
Note:- Mitigation is available, hence making this detection practice.
Splunk Enterprise is affected by multiple vulnerabilities:
Affected Versions:
Splunk Enterprise 8.1.12 and lower
Splunk Enterprise 8.2.0 to 8.2.9
Splunk Enterprise 9.0.0 to 9.0.3
QID Detection Logic(Authenticated)
It checks for vulnerable version of Splunk Enterprise .
Successful exploitation of these vulnerability may allow an Local Privilege Escalation Vulnerability
Solution
Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2023-0207
Vendor References
- SVD-2023-0207 -
advisory.splunk.com/advisories/SVD-2023-0207
CVEs related to QID 378023
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0207 |
|