Getting Data In

vulnerability CVE-2022-32158 16_06_2022 versions before 9.0 Splunk

splunkcol
Builder

Hello,

I see that there is a new vulnerability that affects Splunk and I have a couple of doubts

https://www.splunk.com/en_us/product-security/announcements/svd-2022-0608.html

Excuse me if the question is silly but what is not clear to me is if I should update the version of Splunk Enterprise as SIEM or if I should update only the agents on the endpoints.

Or both?

Thank you for your answers

 

 

"

Description

Splunk Enterprise deployment servers in versions before 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server. 

The Splunk Cloud Platform (SCP) does not offer or use deployment servers and is not affected by the vulnerability. For SCP customers that run deployment servers, upgrade to version 9.0 or higher. At the time of publishing, we have no evidence of exploitation of this vulnerability by external parties.

 

Solution

Upgrade Splunk Enterprise deployment servers to version 9.0 or higher

"

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@splunkcol - The issue is with the Forwarder management (Deployment server) component, so if you are not using then you don't have to worry about it.

 

I hope this helps!!!

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

@splunkcol - Earlier the resolution said you need to update everything to Splunk 9.0.

But the change log says you need to just update the Deployment Server to 9.0

VatsalJagani_0-1655394766854.png

 

I hope this helps!!!

splunkcol
Builder

I usually download and install Splunk enterprise, then ask my clients to install the agent (Universal forwarder) for log forwarding.

In the installation wizard there is a step called "Deployment server" I omit that step, that is, I do not use deployment server.

So should I update Splunk? or update the agent on each endpoint? or not update anything because I don't use deployment server?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@splunkcol - The issue is with the Forwarder management (Deployment server) component, so if you are not using then you don't have to worry about it.

 

I hope this helps!!!

sam79
Engager

Hi, does anyone know if you can just upgrade the deployment server to version 9? Would it be backwards compatible?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Splunk Doc says:

VatsalJagani_0-1655443231993.png

https://docs.splunk.com/Documentation/Splunk/9.0.0/Updating/Planadeployment 

So it's definitely supporting Splunk version above 8.1.x. It probably works prior versions as well but it's not supported.

 

I hope this helps!!!

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...