QID 379121
Date Published: 2024-02-27
QID 379121: Splunk Universal Forwarder Denial of Service (DoS) Vulnerability (SVD-2022-0803)
Splunk Universal Forwarders provide reliable, secure data collection from remote sources and forward that data into Splunk software for indexing and consolidation.
CVE-2022-37439: In Splunk Universal Forwarder versions indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application.
Affected Versions:
Splunk Universal Forwarder versions before 8.1.11
Splunk Universal Forwarder versions 8.2.0 prior to 8.2.7.1
QID Detection Logic (Authenticated):
Windows: This QID checks for installed vulnerable version of Splunk Universal Forwarder using registry "HKLM\SYSTEM\CurrentControlSet\Services\SplunkForwarder"
Successful exploitation of this vulnerability may cause Denial of Service (DoS)
CVEs related to QID 379121
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0803 |
|