QID 730494
Date Published: 2022-05-17
QID 730494: Splunk Enterprise Denial of Service (DoS) Vulnerability (SVD-2022-0301)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2021-3422: The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic.
Affected Versions:
Splunk Enterprise versions prior to 7.3.9
Splunk Enterprise versions 8.0.x prior to 8.0.9
Splunk Enterprise versions 8.1.x prior to 8.1.3
NOTE:
Splunk Enterprise Universal Forwarder component is not affected, so marking it potential.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise by making a request to the account/login/ URL.
Successful exploitation of these vulnerability may allow an unauthenticated attacker to cause denial of service and unavailability of splunk services.
CVEs related to QID 730494
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0301 |
|