Splunk Enterprise

How to upgrade OpenSSL on Splunk servers?

danielbb
Motivator

We have this Tenable vulnerability on some of our Splunk servers - https://www.tenable.com/plugins/nessus/266318

And the solution specified is - "Upgrade to OpenSSL version 1.0.2zm or later." We are running Splunk on-prem 9.3.3, and we wonder, what would be the correct way to upgrade OpenSSL with Splunk running?

I ran the following two commands, and I see different versions -

$openssl version

OpenSSL 1.1.1k FIPS 25 Mar 2021

$./splunk cmd openssl version

OpenSSL 1.0.2zk-fips 3 Sep 2024

Labels (2)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'm sorry but has anyone of your "vulnerability management" team actually read the description of this "finding"? Has anyone bothered to ask what this is about and is there even a remote chance that the "vulnerable" functionality is used anywhere in your Splunk environment? Hey, has anyone bothered to even verify the finding instead of relying on the banner and assuming the library didn't get a backported fix? (relatively unprobable but still possible).

Or is it just "oh, something's not green, let's make it all green!" approach?

livehybrid
SplunkTrust
SplunkTrust

Hi @danielbb 

You cannot/shouldnt upgrade individual components of the packaged Splunk service as this risks breaking things and is not supported. 

An updated OpenSSL binary is likely in an upcoming version. 

In the meantime I would raise this with your Splunk account team and take other mitigations where possible.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...