We have this Tenable vulnerability on some of our Splunk servers - https://www.tenable.com/plugins/nessus/266318
And the solution specified is - "Upgrade to OpenSSL version 1.0.2zm or later." We are running Splunk on-prem 9.3.3, and we wonder, what would be the correct way to upgrade OpenSSL with Splunk running?
I ran the following two commands, and I see different versions -
$openssl version
OpenSSL 1.1.1k FIPS 25 Mar 2021
$./splunk cmd openssl version
OpenSSL 1.0.2zk-fips 3 Sep 2024
I'm sorry but has anyone of your "vulnerability management" team actually read the description of this "finding"? Has anyone bothered to ask what this is about and is there even a remote chance that the "vulnerable" functionality is used anywhere in your Splunk environment? Hey, has anyone bothered to even verify the finding instead of relying on the banner and assuming the library didn't get a backported fix? (relatively unprobable but still possible).
Or is it just "oh, something's not green, let's make it all green!" approach?
Hi @danielbb
You cannot/shouldnt upgrade individual components of the packaged Splunk service as this risks breaking things and is not supported.
An updated OpenSSL binary is likely in an upcoming version.
In the meantime I would raise this with your Splunk account team and take other mitigations where possible.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing