<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk &amp;lt; 7.0.1 - Information Disclosure in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-lt-7-0-1-Information-Disclosure/m-p/381609#M7656</link>
    <description>&lt;P&gt;If/when there is an official response, it will appear on: &lt;A href="https://www.splunk.com/page/securityportal/"&gt;https://www.splunk.com/page/securityportal/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;UPDATE official response: &lt;A href="https://www.splunk.com/view/SP-CAAAP5E"&gt;https://www.splunk.com/view/SP-CAAAP5E&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As of Splunk 6.6 that endpoint requires authentication: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/Installation/Aboutupgradingto6.6READTHISFIRST#Protection_for_the_.27.2Fserver.2Finfo.27_REST_endpoint_is_now_on_by_default"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/Installation/Aboutupgradingto6.6READTHISFIRST#Protection_for_the_.27.2Fserver.2Finfo.27_REST_endpoint_is_now_on_by_default&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As far as the "license keys" that are exposed, I don't know much about this endpoint, but to my untrained eye they look like they're hashes of the license files.&lt;BR /&gt;
(An actual license is a signed XML file, for example see this expired license used as part of tests for the Java SDK: &lt;A href="https://github.com/splunk/splunk-sdk-java/blob/master/tests/com/splunk/splunk_at_least_cupcake.license"&gt;https://github.com/splunk/splunk-sdk-java/blob/master/tests/com/splunk/splunk_at_least_cupcake.license&lt;/A&gt; )&lt;/P&gt;

&lt;P&gt;REST Endpoint Description: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/RESTREF/RESTintrospect#server.2Finfo"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.1/RESTREF/RESTintrospect#server.2Finfo&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jun 2018 02:11:38 GMT</pubDate>
    <dc:creator>acharlieh</dc:creator>
    <dc:date>2018-06-13T02:11:38Z</dc:date>
    <item>
      <title>Splunk &lt; 7.0.1 - Information Disclosure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-lt-7-0-1-Information-Disclosure/m-p/381608#M7655</link>
      <description>&lt;P&gt;Hi Splunkers! Is there any solutions for this right now?&lt;/P&gt;

&lt;P&gt;Splunk &amp;lt; 7.0.1 - Information Disclosure - CVE: CVE-2018-11409&lt;/P&gt;

&lt;P&gt;link: &lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2018-11409"&gt;https://nvd.nist.gov/vuln/detail/CVE-2018-11409&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 18:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-lt-7-0-1-Information-Disclosure/m-p/381608#M7655</guid>
      <dc:creator>sarwshai</dc:creator>
      <dc:date>2018-06-12T18:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk &lt; 7.0.1 - Information Disclosure</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-lt-7-0-1-Information-Disclosure/m-p/381609#M7656</link>
      <description>&lt;P&gt;If/when there is an official response, it will appear on: &lt;A href="https://www.splunk.com/page/securityportal/"&gt;https://www.splunk.com/page/securityportal/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;UPDATE official response: &lt;A href="https://www.splunk.com/view/SP-CAAAP5E"&gt;https://www.splunk.com/view/SP-CAAAP5E&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As of Splunk 6.6 that endpoint requires authentication: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/Installation/Aboutupgradingto6.6READTHISFIRST#Protection_for_the_.27.2Fserver.2Finfo.27_REST_endpoint_is_now_on_by_default"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/Installation/Aboutupgradingto6.6READTHISFIRST#Protection_for_the_.27.2Fserver.2Finfo.27_REST_endpoint_is_now_on_by_default&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As far as the "license keys" that are exposed, I don't know much about this endpoint, but to my untrained eye they look like they're hashes of the license files.&lt;BR /&gt;
(An actual license is a signed XML file, for example see this expired license used as part of tests for the Java SDK: &lt;A href="https://github.com/splunk/splunk-sdk-java/blob/master/tests/com/splunk/splunk_at_least_cupcake.license"&gt;https://github.com/splunk/splunk-sdk-java/blob/master/tests/com/splunk/splunk_at_least_cupcake.license&lt;/A&gt; )&lt;/P&gt;

&lt;P&gt;REST Endpoint Description: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/RESTREF/RESTintrospect#server.2Finfo"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.1/RESTREF/RESTintrospect#server.2Finfo&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 02:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-lt-7-0-1-Information-Disclosure/m-p/381609#M7656</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2018-06-13T02:11:38Z</dc:date>
    </item>
  </channel>
</rss>

