QID 379117
Date Published: 2024-02-19
QID 379117: Splunk Enterprise App Path Traversal Vulnerability (SVD-2023-0608)
Splunk software helps capture, index and correlate real-time data in a searchable repository, from which it can generate graphs, reports, alerts, dashboards and visualizations.
CVE-2023-32714: A low-privileged user with access to the Splunk App for Lookup File Editing can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.
Affected Versions:
Splunk Enterprise versions: from 9.0.0 prior to 9.0.5
Splunk Enterprise versions: from 8.2.0 prior to 8.2.11
Splunk Enterprise versions: from 8.1.0 prior to 8.1.14
Splunk App versions: version before 4.0.1
QID Detection Logic (Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploitation of this vulnerability allows a low-privileged user with access to the Splunk App for Lookup File Editing can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory.
- SVD-2023-0608 -
advisory.splunk.com/advisories/SVD-2023-0608
CVEs related to QID 379117
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2023-0608 |
|