QID 378600
Date Published: 2023-06-21
QID 378600: Splunk Enterprise Information Disclosure Vulnerability (SVD-2023-0609)
A low-privileged user can perform an unauthorized transfer of data from a search using the copyresults command if they know the search ID (SID) of a search job that has recently run.
Affected Versions:
Splunk versions 8.1.0 to 8.1.13
Splunk versions 8.2.0 to 8.2.10
Splunk versions 9.0.0 to 9.0.4
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable.
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploitation may lead to Information Disclosure Vulnerability
- SVD-2023-0609 -
advisory.splunk.com/advisories/SVD-2023-0609
CVEs related to QID 378600
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0609 |
|