QID 730525
Date Published: 2022-06-22
QID 730525: Splunk Enterprise Arbitrary Code Execution Vulnerability (SVD-2022-0608)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2021-42743: A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 9.0 on Windows.
Affected Versions:
Splunk Enterprise versions prior to 9.0
NOTE:
Splunk Enterprise Universal Forwarder component is not affected, so marking it potential.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise by making a request to the account/login/ URL.
Successful exploitation of these vulnerability may allow an unauthenticated attacker to cause arbitrary code execution of splunk services.
CVEs related to QID 730525
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| svd-2022-0608 |
|