QID 378036
Date Published: 2023-04-05
QID 378036: Splunk Enterprise Drilldown Vulnerability CVE-2022-37438 (SVD-2022-0802)
An authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user through the drilldown component. The vulnerability requires user access to create and share dashboards using Splunk Web.
Affected Versions:
Splunk Enterprise versions prior to 8.1.10
Splunk Enterprise versions prior to 8.2.7
Splunk Enterprise versions 9.0.0
QID Detection Logic(Authenticated)
It checks for vulnerable version of Splunk Enterprise .
Splunk drilldown vulnerability disclosure in Dashboard application that can potentially allow exposure of tokens from privilege users. An attacker can create dashboard and share it to privileged user (admin) and detokenize variables using external urls within dashboards drilldown function.
- SVD-2022-0802 -
advisory.splunk.com/advisories/SVD-2022-0802
CVEs related to QID 378036
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0802 |
|