QID 378612
Date Published: 2023-06-29
QID 378612: Splunk Enterprise Hypertext Transfer Protocol (HTTP) Response Splitting Vulnerability (SVD-2023-0603)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2023-32708: A low-privileged user can trigger an HTTP response splitting vulnerability with the 'rest' SPL command that lets them potentially access other REST endpoints in the system arbitrarily, including viewing restricted content.
Affected Versions:
Splunk Enterprise versions from 8.1.0 prior to 8.1.14
Splunk Enterprise versions from 8.2.0 prior to 8.2.11
Splunk Enterprise versions from 9.0.0 prior to 9.0.5
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Successful exploitation of this vulnerability may allow low-privileged user can trigger an HTTP response splitting vulnerability with the 'rest' SPL command that lets them potentially access other REST endpoints in the system arbitrarily, including viewing restricted content.
Workaround:
For Splunk Enterprise, limit the number of searches a process can run by editing the limits.conf configuration file and giving the 'max_searches_per_process' setting a value of either 1 or 0.
- SVD-2023-0603 -
advisory.splunk.com/advisories/SVD-2023-0603
CVEs related to QID 378612
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0603 |
|