QID 378037
Date Published: 2023-05-23
QID 378037: Splunk Enterprise Reflected Cross-Site Scripting (XSS) Vulnerability (SVD-2022-1108)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output mode=radio.
Affected Versions:
Splunk Enterprise versions prior to 8.1.12, 8.2.9 and 9.0.2
NOTE:
The vulnerability affects instances with Splunk Web enabled.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise.
The vulnerability may lead for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON)
Solution
Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2022-1108
Vendor References
- SVD-2022-1108 -
advisory.splunk.com/advisories/SVD-2022-1108
CVEs related to QID 378037
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1108 |
|