QID 730315
Date Published: 2021-12-28
QID 730315: Splunk Enterprise and Light Security Update (SP-CAAAPSV) (SPL-128812)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
Splunk Enterprise and Light versions are affected by multiple vulnerabilities in Python.
Affected Versions:
Splunk Enterprise versions 6.5.x before 6.5.1
Splunk Enterprise versions 6.4.x before 6.4.5
Splunk Enterprise versions 6.3.x before 6.3.8
Splunk Enterprise versions 6.2.x before 6.2.12
Splunk Enterprise versions 6.1.x before 6.1.12
Splunk Enterprise versions 6.0.x before 6.0.13
Splunk Enterprise versions 5.0.x before 5.0.17
Splunk Light versions prior to 6.5.1
NOTE:
Splunk Enterprise Universal Forwarder component is not affected, so marking it potential.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise and Light by making a request to the account/login/ URL.
Successful exploitation of these vulnerabilities may affect Confidentiality, Integrity and Availability.
- SP-CAAAPSV (SPL-128812) -
www.splunk.com/en_us/product-security/announcements-archive/SP-CAAAPSV.html
CVEs related to QID 730315
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SP-CAAAPSV (SPL-128812) |
|