Splunk Enterprise Security

XSS Vulnerability in 6.2.5 build 272645?

ddavenpo
Explorer

Our vulnerability scanner found the following "XSS vulnerability" - Can someone speak to the validity of this or why it might be a false positive? Any assistance would be greatly appreciated.

Injected into the "CiHiliteType" URL parameter (Using method GET) in https://[splunk_server_ip]/null.htw?CiWebHitsFile=/<script>xss</script>.aspx&CiRestriction=none&CiHiliteType=Full by changing the URL to https://[splunk_server_ip]/null.htw?CiWebHitsFile=/<script>xss</script>.aspx&CiRestriction=none&CiHiliteType=\"><script>248484113

1: <!doctype html><html><head><meta http-equiv="content-type" content=...
2: var hashTag = '', hashPos = document.location.href.indexOf('#');
3: if (hashPos > -1) { hashTag = document.location.href.substr(hashPos...
4: ...iHiliteType=\\"><script>248484113" + hashTag;

Tags (3)
0 Karma
1 Solution

chrisg_splunk
Splunk Employee
Splunk Employee

Good day!

In the future, please report security concerns via support if you have a support agreement or via the Splunk Product Security Portal http://www.splunk.com/page/securityportal

This is a false positive for 2 reasons:

  1. This request is generating a 303 redirection page and there are no supported browsers that we are aware of that interpret Javascript in this context.
  2. The context that the issue is a Javascript string parsing context. The input string cannot escape the context due to the presence of other encoding rules.

Thanks for the report and please use the portal in the future in case this isn't a false positive issue and we need to deliver a fix to you and other customers!

View solution in original post

chrisg_splunk
Splunk Employee
Splunk Employee

Good day!

In the future, please report security concerns via support if you have a support agreement or via the Splunk Product Security Portal http://www.splunk.com/page/securityportal

This is a false positive for 2 reasons:

  1. This request is generating a 303 redirection page and there are no supported browsers that we are aware of that interpret Javascript in this context.
  2. The context that the issue is a Javascript string parsing context. The input string cannot escape the context due to the presence of other encoding rules.

Thanks for the report and please use the portal in the future in case this isn't a false positive issue and we need to deliver a fix to you and other customers!

ddavenpo
Explorer

Thanks for the answer and pointing me to the right place!

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...