<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sensitive Information disclosure ? Splunk 8.0.0 in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531326#M11977</link>
    <description>&lt;P&gt;Yeah I checked those and I am fine with them.&lt;/P&gt;&lt;P&gt;The problem is that according to a pentest, it publicly exposes config data.&lt;/P&gt;&lt;P&gt;So I now need to show that it is actually fine (but not finding docs for that is not helping) or I need to block those URLs.&lt;/P&gt;&lt;P&gt;Looks like it is not possible via configuration and I would really like not having to keep a set of rules on the network devices.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2020 14:03:08 GMT</pubDate>
    <dc:creator>randre</dc:creator>
    <dc:date>2020-11-30T14:03:08Z</dc:date>
    <item>
      <title>Splunk 8.0.0: Sensitive Information disclosure?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/530780#M11966</link>
      <description>&lt;P&gt;I have got a pentest results with the following :&lt;/P&gt;
&lt;P&gt;It was possible to access those endpoints unauthenticated :&lt;/P&gt;
&lt;P data-unlink="true"&gt;https://x.x.x.x/en-US/config&lt;BR /&gt;https://x.x.x.x/en-GB/config&lt;BR /&gt;https://x.x.x.x/en-US/info&lt;BR /&gt;https://x.x.x.x/en-US/paths&lt;BR /&gt;https://x.x.x.x/en-us/lists&lt;BR /&gt;https://x.x.x.x/en-US/embed&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it really a vulnerability ? They said that it's config data, not public data so it should not be visible.&lt;/P&gt;
&lt;P&gt;How can we remove those endpoints from being reached unauthenticated ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 04:18:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/530780#M11966</guid>
      <dc:creator>randre</dc:creator>
      <dc:date>2020-12-02T04:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Information disclosure ? Splunk 8.0.0</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/530818#M11968</link>
      <description>&lt;P&gt;Perhaps your firewall can be used to restrict access to those endpoints.&amp;nbsp; They'll still be open, but the risk will be lower.&lt;/P&gt;&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;acceptFrom&lt;/FONT&gt; attribute in server.conf may help limit access to the endpoints.&lt;/P&gt;&lt;P&gt;You can try setting &lt;FONT face="courier new,courier"&gt;requireAuthentication = true&lt;/FONT&gt; in restmap.conf, but I don't know if this will do what you want.&amp;nbsp; Try it on a test system first.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 13:43:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/530818#M11968</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-25T13:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Information disclosure ? Splunk 8.0.0</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531290#M11975</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;requireAuthentication&lt;/FONT&gt; defaults to true anyway so it should not fix my issue.&lt;/P&gt;&lt;P&gt;And I have to keep &lt;FONT face="courier new,courier"&gt;acceptFrom&lt;/FONT&gt; *&lt;/P&gt;&lt;P&gt;My problem is that I don't find documentation about those endpoints so I am not even sure it's a security issue.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 08:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531290#M11975</guid>
      <dc:creator>randre</dc:creator>
      <dc:date>2020-11-30T08:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Information disclosure ? Splunk 8.0.0</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531323#M11976</link>
      <description>&lt;P&gt;Try the endpoints yourself to see what they return.&amp;nbsp; If you don't like what comes out then it's a security issue.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 13:48:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531323#M11976</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-30T13:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Information disclosure ? Splunk 8.0.0</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531326#M11977</link>
      <description>&lt;P&gt;Yeah I checked those and I am fine with them.&lt;/P&gt;&lt;P&gt;The problem is that according to a pentest, it publicly exposes config data.&lt;/P&gt;&lt;P&gt;So I now need to show that it is actually fine (but not finding docs for that is not helping) or I need to block those URLs.&lt;/P&gt;&lt;P&gt;Looks like it is not possible via configuration and I would really like not having to keep a set of rules on the network devices.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 14:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531326#M11977</guid>
      <dc:creator>randre</dc:creator>
      <dc:date>2020-11-30T14:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Information disclosure ? Splunk 8.0.0</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531339#M11978</link>
      <description>&lt;P&gt;The pentest is one opinion; yours is another.&amp;nbsp; You know more about Splunk so your opinion should count for more.&amp;nbsp; If you believe the information disclosed is not a problem then you should be able to convince your company to accept that over the pentest results.&lt;/P&gt;&lt;P&gt;The endpoints should be documented in the REST API manual, but that will detail the requests and responses.&amp;nbsp; It won't say "this is not a vulnerability".&amp;nbsp; It's up to you to make that decision.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 15:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531339#M11978</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-30T15:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Information disclosure ? Splunk 8.0.0</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531606#M11985</link>
      <description>&lt;P&gt;Is it the REST API though ?&lt;/P&gt;&lt;P&gt;Like I said I was not able to find documentation about those endpoints.&lt;/P&gt;&lt;P&gt;Sounds silly but if you can find it that would great... (and would also be troublesome for me).&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 21:48:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531606#M11985</guid>
      <dc:creator>randre</dc:creator>
      <dc:date>2020-12-01T21:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sensitive Information disclosure ? Splunk 8.0.0</title>
      <link>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531696#M11987</link>
      <description>&lt;P&gt;I said it&amp;nbsp;&lt;EM&gt;should&lt;/EM&gt; be in the REST API manual, not that it&amp;nbsp;&lt;EM&gt;is&lt;/EM&gt;.&amp;nbsp; If you find an endpoint that is not documented then consider submitting feedback on the API manual so it can be included.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 13:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-8-0-0-Sensitive-Information-disclosure/m-p/531696#M11987</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-02T13:53:07Z</dc:date>
    </item>
  </channel>
</rss>

