Skip to content
VulniPulse

Splunk Splunk Enterprise Vulnerabilities & Security Advisories

185 advisories tracked · Splunk (prodsec@splunk.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Splunk advisory that VulniPulse classified as Splunk Enterprise, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 81 high, 90 medium, 4 low.

Android app · Google Play

Monitor Splunk CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

Splunk (prodsec@splunk.com CNA) via NVD

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Latest Splunk Splunk Enterprise advisories

High7.5Splunk

High [CVE-2021-31559] crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1…

A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders.

CVE-2021-31559
Splunk EnterpriseUniversal Forwarder
May 6, 2022
High8.1Splunk

High [CVE-2021-26253] potential vulnerability in Splunk Enterprise's implementation of DUO MFA

A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and does not impact or affect a DUO product or service.

CVE-2021-26253
Splunk Enterprise
May 6, 2022
Medium4.3Splunk

Medium [CVE-2022-26070] Splunk Enterprise: When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response

When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.

CVE-2022-26070
Splunk Enterprise
May 6, 2022
Medium5.3Splunk

Medium [CVE-2021-33845] Splunk Enterprise: The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message.

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.

CVE-2021-33845
Splunk Enterprise
May 6, 2022
High7.5Splunk

High [CVE-2021-3422] Splunk Enterprise: The lack of validation of a key-value field in the Splunk-to-Splunk protocol

The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS or a Token, the attack requires compromising the certificate or token, or both. Implementation of either or both reduces the severity to Medium.

CVE-2021-3422
Splunk EnterpriseUniversal Forwarder
Mar 25, 2022

← All Splunk advisories