QID 378042
Date Published: 2023-04-25
QID 378042: Splunk Enterprise Remote Code Execution (RCE) Vulnerability (SVD-2022-1107)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
Affected Versions:
Splunk Enterprise versions prior to 8.1.12, 8.2.9 and 9.0.2
NOTE:
The vulnerability affects instances with Splunk Secure Gateway app. Removing, disabling, or uninstalling the app or restricting access to the app to administrators remediates the vulnerability.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise.
The vulnerability may run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
The vulnerability requires access to the Splunk Secure Gateway app. Removing, disabling, or uninstalling the app or restricting access to the app to administrators remediates the vulnerability.
- SVD-2022-1107 -
advisory.splunk.com/advisories/SVD-2022-1107
CVEs related to QID 378042
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1107 |
|