QID 378866
Date Published: 2023-10-31
QID 378866: Splunk Enterprise Cross-Site Scripting (XSS) Vulnerability (SVD-2022-1101)
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.
CVE-2022-43562.
Affected Versions:
Splunk Enterprise versions from 8.1.0 prior to 8.1.12
Splunk Enterprise versions from 8.2.0 prior to 8.2.9
Splunk Enterprise versions from 9.0.0 prior to 9.0.2
Note: This QID does not checks for the workaround, hence kept as practice.
QID Detection Logic (Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Successful exploitation may lead to cross-site scripting Vulnerability
- SVD-2022-1101 -
advisory.splunk.com/advisories/SVD-2022-1101
CVEs related to QID 378866
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1101 |
|