QID 730652
QID 730652: Splunk Enterprise Search Injection Vulnerability (SVD-2022-0604)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2022-32154: Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request.
Affected Versions:
Splunk Enterprise versions prior to 9.0.0
NOTE:
The vulnerability affects instances with Splunk Web enabled.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise by making a request to the account/login/ URL.
Successful exploitation of this vulnerability may allow an attacker to initiate a request within the victim's browser (e.g., phishing) or compromise an authorized user's account.
CVEs related to QID 730652
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0604 |
|