Vulnerabilities fixed in Splunk Enterprise and Splunk Cloud Platform (advisories.ncsc.nl)
- Insufficient CSRF protection and input validation in Deployment Server endpoints
- Path traversal during app installation to $SPLUNK_HOME/etc/
- Credential hash access via REST endpoint without admin privileges
"Splunk has fixed three vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. The first involves insufficient CSRF protection and input validation in Deployment Server endpoints, allowing arbitrary SPL searches under the splunk-system-user context with elevated privileges. The second is a path traversal issue when installing apps, enabling writing files outside the app directory into $SPLUNK_HOME/etc/. The third allows non-admin users to access stored credential hashes via REST endpoints and SPL commands. These affect data confidentiality and integrity."
no comments yet.