Skip to content
VulniPulse

Splunk Security Advisories & CVEs

243 advisories tracked · Splunk (prodsec@splunk.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Splunk CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your Splunk device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Splunk's recent advisories.

Official source

Splunk (prodsec@splunk.com CNA) via NVD

Splunk is its own CVE Numbering Authority. VulniPulse ingests Splunk's CVEs from the NVD CNA feed (prodsec@splunk.com), each linking to its SVD-YYYY-NNNN advisory on advisory.splunk.com. Covers Splunk Enterprise, Splunk Cloud Platform, the Universal Forwarder, IT Service Intelligence (ITSI), SOAR, Enterprise Security and Splunk apps/add-ons — the SIEM at the centre of most SOCs, so a security-team audience that patches on advisory day.

Latest Splunk advisories

Medium4.3Splunk

Medium [CVE-2022-26070] Splunk Enterprise: When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response

When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The vulnerability impacts Splunk Enterprise versions before 8.1.0.

CVE-2022-26070
Splunk Enterprise
May 6, 2022
Medium5.3Splunk

Medium [CVE-2021-33845] Splunk Enterprise: The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message.

The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerability impacts Splunk Enterprise instances before 8.1.7 when configured to repress verbose login errors.

CVE-2021-33845
Splunk Enterprise
May 6, 2022
High7.5Splunk

High [CVE-2021-3422] Splunk Enterprise: The lack of validation of a key-value field in the Splunk-to-Splunk protocol

The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS or a Token, the attack requires compromising the certificate or token, or both. Implementation of either or both reduces the severity to Medium.

CVE-2021-3422
Splunk EnterpriseUniversal Forwarder
Mar 25, 2022

← All vendors