QID 378599

Date Published: 2023-06-21

QID 378599: Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in versions 8.1.14, 8.2.11, and 9.0.5 of Splunk Enterprise

Affected Versions:
Splunk versions 8.1 prior to 8.1.14
Splunk versions 8.2 prior to 8.2.11
Splunk versions 9.0 prior to 9.0.5

QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable.
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".

Successful exploitation can crash Splunk.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2023-0613 for more details.

    Vendor References

    CVEs related to QID 378599

    CVE-2022-40303 | CVE-2022-40304 | CVE-2023-0286 | CVE-2023-0215 | CVE-2022-4304 | CVE-2023-27538 | CVE-2023-27537 | CVE-2023-27536 | CVE-2023-27535 | CVE-2023-27534 | CVE-2023-27533 | CVE-2023-23916 | CVE-2023-23915 | CVE-2023-23914 | CVE-2022-43552 | CVE-2022-43551 | CVE-2022-42916 | CVE-2022-42915 | CVE-2022-35260 | CVE-2022-32221 | CVE-2022-35252 | CVE-2022-32208 | CVE-2022-32207 | CVE-2022-32206 | CVE-2022-32205 | CVE-2022-30115 | CVE-2022-27782 | CVE-2022-27781 | CVE-2022-27780 | CVE-2022-27779 | CVE-2022-27778 | CVE-2022-27776 | CVE-2022-27775 | CVE-2022-27774 | CVE-2022-22576 | CVE-2021-22947 | CVE-2021-22946 | CVE-2021-22945 | CVE-2021-22926 | CVE-2021-22925 | CVE-2021-22924 | CVE-2021-22923 | CVE-2021-22922 | CVE-2021-22901 | CVE-2021-22898 | CVE-2021-22897 | CVE-2021-22890 | CVE-2021-22876 | CVE-2020-8286 | CVE-2020-8285 | CVE-2020-8284 | CVE-2020-8231 | CVE-2020-8177 | CVE-2020-8169 | CVE-2022-36227 | CVE-2021-31566 | CVE-2021-36976 | CVE-2021-3520 | CVE-2022-35737 | CVE-2018-25032 | CVE-2022-37434 | CVE-2020-15138 | CVE-2022-37616 | CVE-2022-23491 | CVE-2021-29060 | CVE-2022-38900 | CVE-2020-28469 | CVE-2022-46175 | CVE-2022-46175 | CVE-2022-37599 | CVE-2022-37601 | CVE-2022-37603 | CVE-2022-3517 | CVE-2022-31129 | CVE-2021-23343 | CVE-2021-23368 | CVE-2021-23382 | CVE-2022-43680 | CVE-2022-24999 | CVE-2020-7753 | CVE-2022-25858 | CVE-2021-3803 | CVE-2020-7753 | CVE-2021-33587 | CVE-2020-8116 | CVE-2020-13822 | CVE-2022-33987 | CVE-2022-4200 | CVE-2022-42004 | CVE-2023-1370 | CVE-2019-20149 | CVE-2022-37601 | CVE-2022-37601 | CVE-2020-8203 | CVE-2019-10744 | CVE-2022-40023 | CVE-2019-10746 | CVE-2021-23382 | CVE-2021-33502 | CVE-2021-27292 | CVE-2021-33503 | CVE-2020-7662 | CVE-2020-7774 | CVE-2022-23806 | CVE-2022-23772 | CVE-2021-43565 | CVE-2022-30580 | CVE-2022-30633 | CVE-2022-28131 | CVE-2022-30632 | CVE-2022-41716 | CVE-2022-28327 | CVE-2022-24921 | CVE-2022-30630 | CVE-2022-27191 | CVE-2022-23773 | CVE-2022-30634 | CVE-2022-41715 | CVE-2022-24675 | CVE-2022-41720 | CVE-2022-27664 | CVE-2022-2880 | CVE-2022-29804 | CVE-2022-32189 | CVE-2022-30635 | CVE-2022-30631 | CVE-2022-2879 | CVE-2022-1705 | CVE-2022-1962 | CVE-2022-29526 | CVE-2022-32148 | CVE-2022-30629 | CVE-2017-16042 | CVE-2021-20095 |
    Software Advisories
    Advisory ID Software Component Link
    SVD-2023-0613 URL Logo advisory.splunk.com/advisories/SVD-2023-0613