QID 379113
Date Published: 2023-12-28
QID 379113: Splunk Enterprise Third Party Package Updates for November (SVD-2022-1113)
Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in versions 8.1.14, 8.2.11, and 9.0.5 of Splunk Enterprise
Affected Versions:
Splunk versions 8.1 prior to 8.1.12
Splunk versions 8.2 prior to 8.2.9
Splunk versions 9.0 prior to 9.0.2
QID Detection Logic(Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable.
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploit may impact availability
Solution
Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2022-1113 for more details.
Vendor References
- SVD-2022-1113 -
advisory.splunk.com/advisories/SVD-2022-1113
CVEs related to QID 379113
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-1113 |
|