PT-2022-18124 · Splunk · Splunk Enterprise
Jason Tsang Mui Chung
·
Published
2022-05-06
·
Updated
2022-10-19
·
CVE-2022-26889
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 8.1.2
Description
The issue allows an attacker to potentially inject arbitrary content into a web page, such as HTML Injection or XSS, or bypass safeguards for risky commands. This is due to a path traversal vulnerability in the uri path to load a relative resource within a web page. The attack is browser-based and requires an attacker to initiate a request within the victim's browser, such as through phishing. The lack of sanitization in a relative url path in a search parameter enables the arbitrary injection of external content.
Recommendations
For Splunk Enterprise versions prior to 8.1.2, update to version 8.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive web pages and implementing additional security measures to prevent phishing attacks. Avoid using the vulnerable search parameter until the issue is resolved.
Fix
Path traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Splunk Enterprise