QID 378054
Date Published: 2023-03-29
QID 378054: Splunk Enterprise Reflected Cross-Site Scripting (XSS) Vulnerability in Monitoring Console (SVD-2022-0505)
The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4.
Note:- Mitigation is available, hence making this detection practice.
Affected Versions:
Splunk Enterprise 8.1.3 and lower
QID Detection Logic(Authenticated)
It checks for vulnerable version of Splunk Enterprise
Successful exploitation may lead to impacting confidentiality, availability and integrity
Solution
Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2022-0505
Vendor References
- SVD-2022-0505 -
advisory.splunk.com/advisories/SVD-2022-0505
CVEs related to QID 378054
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0505 |
|