QID 730521

Date Published: 2022-06-22

QID 730521: Splunk Enterprise Local Privilege Escalation Vulnerability (SVD-2022-0501)

Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.

CVE-2021-42743: A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows.

Affected Versions:
Splunk Enterprise versions prior to 8.1.1
NOTE:
Splunk Enterprise Universal Forwarder component is not affected, so marking it potential.

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise by making a request to the account/login/ URL.

Successful exploitation of these vulnerability may allow an unauthenticated attacker to cause local privilege escalation of splunk services.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to refer to latest release SVD-2022-0501 for updates pertaining to these vulnerabilities.

    CVEs related to QID 730521

    Software Advisories
    Advisory ID Software Component Link
    svd-2022-0501 URL Logo www.splunk.com/en_us/product-security/announcements/svd-2022-0501.html