Security

How we can resolve this RCE in Splunk Enterprise through Insecure XML Parsing issue

AL3Z
Builder

Hi,

We have been informed about a high-severity vulnerability (CVE-2023-46214) impacting Splunk Enterprise (RCE in Splunk Enterprise through Insecure XML Parsing)  as we are on Splunk Cloud Version:9.0.2303.201.

Thanks..

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @AL3Z ..

Please check this Splunk Advisory:

https://advisory.splunk.com/advisories/SVD-2023-1104

the Splunk Cloud affected version is - Versions below 9.1.2308

The Splunk Cloud fix version is --------- 9.1.2308

 

So you should ask the Splunk Cloud Support and ask them to upgrade your Splunk Cloud to the fix version 9.1.2308, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

AL3Z
Builder

@inventsekar ,

They  recommended upgrading or updating the web.conf file in on-prem environment.
How we can do this  as its not the cloud its an enterprise.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...