Summary:
Splunk has released critical patches addressing multiple vulnerabilities in Splunk Enterprise, with a notable high-severity bug CVE-2024-23678 affecting Windows instances. The identified flaw involves incorrect sanitization of path input data, leading to unsafe deserialization of untrusted data from a separate disk partition on the machine. This type of vulnerability, known as deserialization of untrusted data, can potentially result in denial of service, abuse of application logic, or execution of arbitrary code. This specific CVE only affects Splunk Enterprise for Windows and has been addressed in versions 9.0.8 and 9.1.3. Additionally, these releases fix several medium-severity vulnerabilities, including issues related to Splunk app key value store (KV Store) permissions, unauthorized access to metrics by low-privileged users, and disclosure of sensitive information in the Splunk RapidDiag utility. The patches also cover ten vulnerabilities in third-party packages, with four rated as critical and four as high severity.[/subscribe_to_unlock_form]
Summary:
Splunk has released critical patches addressing multiple vulnerabilities in Splunk Enterprise, with a notable high-severity bug CVE-2024-23678 affecting Windows instances. The identified flaw involves incorrect sanitization of path input data, leading to unsafe deserialization of untrusted data from a separate disk partition on the machine. This type of vulnerability, known as deserialization of untrusted data, can potentially result in denial of service, abuse of application logic, or execution of arbitrary code. This specific CVE only affects Splunk Enterprise for Windows and has been addressed in versions 9.0.8 and 9.1.3. Additionally, these releases fix several medium-severity vulnerabilities, including issues related to Splunk app key value store (KV Store) permissions, unauthorized access to metrics by low-privileged users, and disclosure of sensitive information in the Splunk RapidDiag utility. The patches also cover ten vulnerabilities in third-party packages, with four rated as critical and four as high severity.[emaillocker id="1283"]
Recommendations:
References:
The following reports contain further technical details:
https://www.securityweek.com/high-severity-vulnerability-patched-in-splunk-enterprise/
[/emaillocker]