QID 730137
Date Published: 2021-10-04
QID 730137: Splunk Enterprise and Light Persistent Cross Site Scripting Vulnerability (SP-CAAAQAF)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
Affected Versions:
Splunk Enterprise versions 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, 6.0.x before 6.0.15
Splunk Light versions prior to 6.6.0
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise and Light by making a request to the account/login/ URL.
Successful exploitation allows an authenticated attacker to inject and store arbitrary JavaScript.
Solution
Customers are advised to refer to latest release SP-CAAAQAF for updates pertaining to these vulnerabilities.
Vendor References
CVEs related to QID 730137
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SP-CAAAQAF |
|