<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XSS SplunkWeb vulnerability in Security</title>
    <link>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154397#M14636</link>
    <description>&lt;P&gt;Hi lboyd, &lt;/P&gt;

&lt;P&gt;Splunk Product Security is aware of this XSS referrer header vulnerability. Engineering has fixed the issue, and updates are coming soon in upcoming maintenance releases. Please stay tuned for more details. &lt;/P&gt;</description>
    <pubDate>Thu, 24 Jul 2014 01:05:28 GMT</pubDate>
    <dc:creator>dwolf_splunk</dc:creator>
    <dc:date>2014-07-24T01:05:28Z</dc:date>
    <item>
      <title>XSS SplunkWeb vulnerability</title>
      <link>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154395#M14634</link>
      <description>&lt;P&gt;Several sources indicate a XSS vulnerability in recent Splunk versions.  I can find no reference to this issue on your site or in the change logs.  Below are some recent examples of sites referring to this issue confirmed in a different Splunk version 6.1.1; our Nessus scanner is also hitting on it(by exploit test and not version check) against version 5.0.8.   &lt;/P&gt;

&lt;P&gt;cn.tenable.com/plugins/index.php?view=single&amp;amp;id=74243&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.securityfocus.com/bid/67655/info"&gt;www.securityfocus.com/bid/67655/info&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;packetstormsecurity.com/files/126813/Splunk-6.1.1-Cross-Site-Scripting.html&lt;/P&gt;

&lt;P&gt;Does the Splunk team have a plan to address this vulnerability?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 15:37:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154395#M14634</guid>
      <dc:creator>lboyd</dc:creator>
      <dc:date>2014-07-23T15:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: XSS SplunkWeb vulnerability</title>
      <link>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154396#M14635</link>
      <description>&lt;P&gt;hi lboyd, someone from our prodsec team will be by soon to respond to your question.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 22:14:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154396#M14635</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2014-07-23T22:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: XSS SplunkWeb vulnerability</title>
      <link>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154397#M14636</link>
      <description>&lt;P&gt;Hi lboyd, &lt;/P&gt;

&lt;P&gt;Splunk Product Security is aware of this XSS referrer header vulnerability. Engineering has fixed the issue, and updates are coming soon in upcoming maintenance releases. Please stay tuned for more details. &lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2014 01:05:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154397#M14636</guid>
      <dc:creator>dwolf_splunk</dc:creator>
      <dc:date>2014-07-24T01:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: XSS SplunkWeb vulnerability</title>
      <link>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154398#M14637</link>
      <description>&lt;P&gt;Is there an ETA when this fix will be released?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2014 13:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154398#M14637</guid>
      <dc:creator>robert_miller</dc:creator>
      <dc:date>2014-07-28T13:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: XSS SplunkWeb vulnerability</title>
      <link>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154399#M14638</link>
      <description>&lt;P&gt;Hi Robert,&lt;/P&gt;

&lt;P&gt;The next maintenance release is in assurance testing and will be published soon. Splunk releases are cumulative, meaning that future releases will contain fixes to vulnerabilities, new features and other bug fixes. Please bear with us while we ensure the new bits work as expected across multiple platforms and configurations.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2014 23:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/XSS-SplunkWeb-vulnerability/m-p/154399#M14638</guid>
      <dc:creator>dwolf_splunk</dc:creator>
      <dc:date>2014-07-28T23:42:44Z</dc:date>
    </item>
  </channel>
</rss>

