QID 378596
Date Published: 2023-06-21
QID 378596: Splunk Enterprise Security Update (SVD-2023-0601) (SVD-2023-0602)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
Affected Versions:
Splunk versions 8.1 prior to 8.1.14
Splunk versions 8.2 prior to 8.2.11
Splunk versions 9.0 prior to 9.0.5
NOTE:
This QID does not check for workaround hence kept as practice.
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable.
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploitation can crash Splunk.
Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2023-0601 for more details.
Workaround:
SVD-2023-0601:Disable single sign-on using SAML as an authentication scheme (SAML SSO). For more information on this type of configuration, see Configure single sign-on with SAML in the Splunk documentation.
SVD-2023-0602:Confirm that no role, other than the admin role or its equivalent, has the edit_user capability assigned to it. Confirm that you neither assign the edit_user capability to a role from which other roles inherit, nor that you assign a role with the capability to a user with low or no privileges.
- , SVD-2023-0602 -
advisory.splunk.com/advisories/SVD-2023-0602 - SVD-2023-0601 -
advisory.splunk.com/advisories/SVD-2023-0601
CVEs related to QID 378596
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0601 |
|