QID 379545

Date Published: 2024-04-02

QID 379545: Splunk Enterprise Third Party Package Updates for March 2024 (SVD-2024-0303)

Splunk software helps capture, index and correlate real-time data in a searchable repository, from which it can generate graphs, reports, alerts, dashboards and visualizations.
Third Party Package updates in Splunk Enterprise

Openssl, net, go, hive-exec, curl, pywin32, jackson-databind

Affected Versions:
Splunk Enterprise versions: 9.0.0 to 9.0.8
Splunk Enterprise versions: 9.1.0 to 9.1.3
Splunk Enterprise versions: from 9.2.0 to 9.2.0.1

QID Detection Logic (Authenticated)
Linux: Checks for installed vulnerable version of Splunk Enterprise from "/etc/splunk.version" file either in "/opt/splunk" directory or using "$SPLUNK_HOME" environment variable along with splunk web configuration check using "/etc/system/default/limit.conf" or "/etc/system/local/limit.conf".
Windows: Checks for installed vulnerable version of Splunk from "/etc/splunk.version" file using registry "HKLM\SYSTEM\CurrentControlSet\Services\Splunkd".

Successful exploitation of this vulnerability may impact confidentiality, integrity and availability

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Vendor has released updated versions to fix these vulnerabilities. Please refer SVD-2024-0303 for more details.

    Vendor References

    CVEs related to QID 379545

    Software Advisories
    Advisory ID Software Component Link
    SVD-2024-0303 URL Logo advisory.splunk.com/advisories/SVD-2024-0303