Security

Splunk log4j

KIMBYEONGGON
New Member

We are using splunk version 6.2.4.

Recently, I received a call saying that a vulnerability was also found in the 1.2.xx version of log4j.

log4j-1.2.14jar and log4j-1.2.15jar files were found on splunk.

I want to know if that jar file is used and if it is vulnerable to security.

thank you.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

first your splunk installation is quite old and out of support. You should plan to update it to supported versions as soon as possible. Oldest supported version is currently 8.1.x. Unfortunately you need some middle versions to reach this target level, which are not available from splunk.com any more. You must contact to Splunk support and ask if they could give those to you.

The current knowledge is the core splunk is used log4j only for DFS and if that is not in use then there shouldn't be an issue. BUT as your version is out of support, I'm not sure if Splunk has verified that for your version (probably not). 

Here is Splunk's information about this vulnerability:

My personal proposal to you is: try to update your splunk to current one as soon as possible.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...