Security

XSS SplunkWeb vulnerability

lboyd
New Member

Several sources indicate a XSS vulnerability in recent Splunk versions. I can find no reference to this issue on your site or in the change logs. Below are some recent examples of sites referring to this issue confirmed in a different Splunk version 6.1.1; our Nessus scanner is also hitting on it(by exploit test and not version check) against version 5.0.8.

cn.tenable.com/plugins/index.php?view=single&id=74243

www.securityfocus.com/bid/67655/info

packetstormsecurity.com/files/126813/Splunk-6.1.1-Cross-Site-Scripting.html

Does the Splunk team have a plan to address this vulnerability?

Tags (2)
0 Karma

dwolf_splunk
Splunk Employee
Splunk Employee

Hi lboyd,

Splunk Product Security is aware of this XSS referrer header vulnerability. Engineering has fixed the issue, and updates are coming soon in upcoming maintenance releases. Please stay tuned for more details.

0 Karma

dwolf_splunk
Splunk Employee
Splunk Employee

Hi Robert,

The next maintenance release is in assurance testing and will be published soon. Splunk releases are cumulative, meaning that future releases will contain fixes to vulnerabilities, new features and other bug fixes. Please bear with us while we ensure the new bits work as expected across multiple platforms and configurations.

0 Karma

robert_miller
Path Finder

Is there an ETA when this fix will be released?

0 Karma

piebob
Splunk Employee
Splunk Employee

hi lboyd, someone from our prodsec team will be by soon to respond to your question.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...