[subscribe_to_unlock_form]
Summary:
Splunk on Wednesday announced patches for multiple high-severity vulnerabilities in Splunk Enterprise and IT Service Intelligence, including flaws in third-party packages.[/subscribe_to_unlock_form]
Summary:
Splunk on Wednesday announced patches for multiple high-severity vulnerabilities in Splunk Enterprise and IT Service Intelligence, including flaws in third-party packages.[emaillocker id="1283"]
- CVE-2023-40592: This is a cross-site scripting (XSS) flaw found in Splunk Enterprise. While not as severe as RCE, it poses a risk by allowing attackers to inject malicious scripts into web applications.
- CVE-2023-40595: This high-severity vulnerability with a CVSS score of 8.8 affects Splunk Enterprise. It enables remote code execution through crafted queries, specifically using the "collect SPL" command. Attackers can write a file within the Splunk Enterprise installation, allowing the execution of code within the payload.
- CVE-2023-40596: This high-severity issue in Splunk Enterprise pertains to a privilege escalation problem caused by an insecure path reference in a DLL.
- CVE-2023-40597: A high-severity vulnerability in Splunk Enterprise, this CVE is related to an absolute path traversal bug, potentially leading to code execution.
- CVE-2023-40598: Another high-severity vulnerability in Splunk Enterprise, this CVE relates to a command injection flaw that impacts a deprecated internal function, specifically the "runshellscript" command. Attackers can exploit this to execute arbitrary commands within a privileged context.
- CVE-2023-4571: In IT Service Intelligence, Splunk addressed an unauthenticated log injection vulnerability. This vulnerability could allow attackers to inject ANSI escape codes into log files. When these logs are read in a vulnerable terminal application, it could lead to the execution of malicious code. The severity of this CVE is rated at 8.6.
Recommendations:
- We strongly recommend you update your Splunk Enterprise installation to one of the following versions: 8.2.12, 9.0.6, or 9.1.1. And using Splunk ITSI, it's crucial to upgrade to version 4.13.3 or 4.15.3 as soon as possible.
References:
The following reports contain further technical details:
https://www.securityweek.com/splunk-patches-high-severity-flaws-in-enterprise-it-service-intelligence/
[/emaillocker]