<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Seeing (SSL/TLS Compression Algorithm Information Leakage Vulnerability	port 8089/tcp over SSL) from qualys scanning in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Seeing-SSL-TLS-Compression-Algorithm-Information-Leakage/m-p/537317#M9653</link>
    <description>&lt;P&gt;We are seeing this vulnerability show up via qualys vuln scanning on both our dev and production splunk instances. I am using the same ssl config for both and have tried solving this multiple ways including the first solution proposed here: &lt;A href="https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126153" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126153&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;this is what our ssl and http server config in server.conf looks like currently:&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;[sslConfig]&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sslPassword = $encryptedsslpass$&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;serverCert = $servercertpath$&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;caCertFile = $cacertpath$&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sendStrictTransportSecurityHeader=true&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;useSSLCompression = false&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;allowSSLCompression = false&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sslVersions = tls1.2&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sslVersionsForClient = tls1.2&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;[httpServer]&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;replyHeader.X-XSS-Protection= 1; mode=block&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;replyHeader.Content-Security-Policy = script-src 'self'; object-src 'self'&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1 lia-align-left"&gt;Is there anything I need to add to this config or elsewhere to solve this vulnerability? I do not want to block the scanner from seeing the port as I have seen proposed in some solutions.&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2021 21:35:34 GMT</pubDate>
    <dc:creator>ncsasecops</dc:creator>
    <dc:date>2021-01-26T21:35:34Z</dc:date>
    <item>
      <title>Seeing (SSL/TLS Compression Algorithm Information Leakage Vulnerability	port 8089/tcp over SSL) from qualys scanning</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Seeing-SSL-TLS-Compression-Algorithm-Information-Leakage/m-p/537317#M9653</link>
      <description>&lt;P&gt;We are seeing this vulnerability show up via qualys vuln scanning on both our dev and production splunk instances. I am using the same ssl config for both and have tried solving this multiple ways including the first solution proposed here: &lt;A href="https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126153" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/I-am-looking-for-clarification-on-SSL-compression-settings-in/m-p/126153&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;this is what our ssl and http server config in server.conf looks like currently:&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;[sslConfig]&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sslPassword = $encryptedsslpass$&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;serverCert = $servercertpath$&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;caCertFile = $cacertpath$&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sendStrictTransportSecurityHeader=true&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;useSSLCompression = false&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;allowSSLCompression = false&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sslVersions = tls1.2&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;sslVersionsForClient = tls1.2&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;[httpServer]&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;replyHeader.X-XSS-Protection= 1; mode=block&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left lia-indent-padding-left-30px"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;replyHeader.Content-Security-Policy = script-src 'self'; object-src 'self'&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1 lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1 lia-align-left"&gt;Is there anything I need to add to this config or elsewhere to solve this vulnerability? I do not want to block the scanner from seeing the port as I have seen proposed in some solutions.&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:35:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Seeing-SSL-TLS-Compression-Algorithm-Information-Leakage/m-p/537317#M9653</guid>
      <dc:creator>ncsasecops</dc:creator>
      <dc:date>2021-01-26T21:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing (SSL/TLS Compression Algorithm Information Leakage Vulnerability	port 8089/tcp over SSL) from qualys scanning</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Seeing-SSL-TLS-Compression-Algorithm-Information-Leakage/m-p/569754#M10337</link>
      <description>&lt;P&gt;I'm having the same issue. Did you ever find a resolution?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 18:16:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Seeing-SSL-TLS-Compression-Algorithm-Information-Leakage/m-p/569754#M10337</guid>
      <dc:creator>CALEX</dc:creator>
      <dc:date>2021-10-05T18:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing (SSL/TLS Compression Algorithm Information Leakage Vulnerability	port 8089/tcp over SSL) from qualys scanning</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Seeing-SSL-TLS-Compression-Algorithm-Information-Leakage/m-p/599242#M10827</link>
      <description>&lt;P&gt;If this is regarding&amp;nbsp;&lt;SPAN&gt;CVE-2012-4929 probably you should check below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-shows-vulnerable-to-CVE-2012-4929-in-my-Nessus/m-p/29091" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-shows-vulnerable-to-CVE-2012-4929-in-my-Nessus/m-p/29091&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 09:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Seeing-SSL-TLS-Compression-Algorithm-Information-Leakage/m-p/599242#M10827</guid>
      <dc:creator>k_sam</dc:creator>
      <dc:date>2022-05-25T09:31:44Z</dc:date>
    </item>
  </channel>
</rss>

