QID 378027
Date Published: 2023-03-21
QID 378027: Splunk Enterprise Denial of Service (DoS) Vulnerability (SVD-2022-1112)
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
Note:- Mitigation is available, hence making this detection practice.
Affected Versions:
Splunk Enterprise 8.1.11 and lower
Splunk Enterprise 8.2.0 to 8.2.8
Splunk Enterprise 9.0.0 to 9.0.1
QID Detection Logic(Authenticated)
It checks for vulnerable version of Splunk Enterprise .
The vulnerability may lead to denial of service
Solution
Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2022-1112
Vendor References
- SVD-2022-1112 -
advisory.splunk.com/advisories/SVD-2022-1112
CVEs related to QID 378027
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1111 |
|