QID 378741
QID 378741: Splunk Enterprise Information Disclosure Vulnerability (SVD-2023-0604)
A low-privileged user who holds the user role can see the hashed version of the initial user name and password for the Splunk instance by using the rest SPL command against the conf-user-seed REST endpoint.
CVE-2023-32709.
Affected Versions:
Splunk Enterprise versions from 8.1.0 prior to 8.1.13
Splunk Enterprise versions from 8.2.0 prior to 8.2.10
Splunk Enterprise versions from 9.0.0 prior to 9.0.4
QID Detection Logic (Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Successful exploitation may lead to Information Disclosure Vulnerability
- SVD-2023-0604 -
advisory.splunk.com/advisories/SVD-2023-0604
CVEs related to QID 378741
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0604 |
|