QID 378454
Date Published: 2023-05-02
QID 378454: Splunk Enterprise Security Update (SVD-2023-0206)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
Affected Versions:
Splunk versions 8.1 prior to 8.1.13
Splunk versions 8.2 prior to 8.2.10
Splunk versions 9.0 prior to 9.0.4
NOTE:
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable.
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploitation may compromise confidentiality, integrity and availability
- SVD-2023-0206 -
advisory.splunk.com/advisories/SVD-2023-0206
CVEs related to QID 378454
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0206 |
|