Security

How we can resolve this RCE in Splunk Enterprise through Insecure XML Parsing issue

AL3Z
Builder

Hi,

We have been informed about a high-severity vulnerability (CVE-2023-46214) impacting Splunk Enterprise (RCE in Splunk Enterprise through Insecure XML Parsing)  as we are on Splunk Cloud Version:9.0.2303.201.

Thanks..

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @AL3Z ..

Please check this Splunk Advisory:

https://advisory.splunk.com/advisories/SVD-2023-1104

the Splunk Cloud affected version is - Versions below 9.1.2308

The Splunk Cloud fix version is --------- 9.1.2308

 

So you should ask the Splunk Cloud Support and ask them to upgrade your Splunk Cloud to the fix version 9.1.2308, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

AL3Z
Builder

@inventsekar ,

They  recommended upgrading or updating the web.conf file in on-prem environment.
How we can do this  as its not the cloud its an enterprise.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...