Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Chris Samley

Researcher fromGE
#37435of 55,140
7.5Total CVSS
Vulnerabilities · 1
PT-2022-10035
7.5
2022-05-06
Splunk · Splunk Enterprise Indexer · CVE-2021-31559
**Name of the Vulnerable Software and Affected Versions** Splunk Enterprise Indexer versions 8.1 through 8.1.4 Splunk Enterprise Indexer versions 8.2 through 8.2.0 **Description** A crafted request can bypass S2S TCP Token authentication, allowing arbitrary events to be written to an index. This issue impacts Indexers configured to use TCPTokens, but it does not affect Universal Forwarders. **Recommendations** For versions 8.1 through 8.1.4, update to version 8.1.5 or later. For versions 8.2 through 8.2.0, update to version 8.2.1 or later.