QID 378739
Date Published: 2023-10-16
QID 378739: Splunk Enterprise Denial of Service (DoS) Vulnerability (SVD-2023-0611)
Splunk Enterprise captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualisations.
CVE-2023-32716: An attacker can exploit a vulnerability in the dump SPL command to cause a denial of service by crashing the Splunk daemon. If the attacker supplies a longer-than-expected filename with the command, a memory access violation, or segmentation fault, occurs, which results in a crash of the Splunk platform instance.
Affected Versions:
Splunk Enterprise versions from 8.1.0 prior to 8.1.13
Splunk Enterprise versions from 8.2.0 prior to 8.2.10
Splunk Enterprise versions from 9.0.0 prior to 9.0.4
QID Detection Logic (Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Successful exploitation of this vulnerability may allow attacker can exploit a vulnerability in the dump SPL command to cause a denial of service by crashing the Splunk daemon.
- SVD-2023-0611 -
advisory.splunk.com/advisories/SVD-2023-0611
CVEs related to QID 378739
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0611 |
|