IHAC running a large C11 On-Prem stack. They are in a bit of a pickle due to unsupported RHEL 7 and halfway through an upgrade from 9.3.x to 9.4.x and are seeking advice on the recent CVE's.
My problem / question is what version of 'golang' is installed with their particular version of Splunk, this is in response to SVD-2025-0603 | Splunk Vulnerability Disclosure
It is not clear how to verify this.
@NullZero The golang versions are embedded in Splunk binaries. To check your current versions:
cd $SPLUNK_HOME/bin
./mongodump --version
./mongorestore --version
You should complete the upgrade to 9.4.2+ immediately - after checking the current golang version if it has critical vulnerabilities that need patching.
If this Helps, Please Upvote.
@NullZero The golang versions are embedded in Splunk binaries. To check your current versions:
cd $SPLUNK_HOME/bin
./mongodump --version
./mongorestore --version
You should complete the upgrade to 9.4.2+ immediately - after checking the current golang version if it has critical vulnerabilities that need patching.
If this Helps, Please Upvote.
Very helpful thanks!