QID 379119
Date Published: 2023-12-21
QID 379119: Splunk Enterprise Denial of Service (DoS) Vulnerability (SVD-2022-0803)
Splunk software helps capture, index and correlate real-time data in a searchable repository, from which it can generate graphs, reports, alerts, dashboards and visualizations.
CVE-2022-37439: In Splunk Enterprise versions indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application.
Affected Versions:
Splunk Enterprise versions before 8.1.11
Splunk Enterprise versions 8.2.0 prior to 8.2.7.1
QID Detection Logic (Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".
Successful exploitation of this vulnerability may cause Denial of Service (DoS)
CVEs related to QID 379119
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0803 |
|