QID 378038
Date Published: 2023-03-13
QID 378038: Splunk Enterprise Security Update (SVD-2022-0604)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
Affected Splunk Enterprise versions inject risky search commands into a form token when the token is used in a query in a cross-origin request.
Affected Versions:
Splunk versions prior to 9.0.0
NOTE:
If you have not and are using the default certificates, the vulnerability is not applicable and is informational.
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable.
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploitation of this vulnerability might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request.
Workaround:
Splunk strongly recommends securing your Splunk environment with hardened TLS configurations.
- SVD-2022-0604 -
advisory.splunk.com/advisories/SVD-2022-0604
CVEs related to QID 378038
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0604 |
|