Splunk Search

A reflected XSS vulnerability in Splunk 4.0 through 4.3?

Hajime
Path Finder

Hi,

Does the reflected cross-site scripting vulnerability (SPL-59895, CVE-2012-6447) affect to Splunk 4.0 through 4.3?

If that versions are affected, please tell me what to do.

Thanks,

Tags (1)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

SPL-59895 (CVE-2012-6447 reserved) is for 5.0.0-5.0.2.

The same issue in 4.3.0-4.3.5 is tracked as SPL-60629 (CVE-2013-2766) and was
fixed in 4.3.6 as announced here:

http://www.splunk.com/view/SP-CAAAHSQ

This was already answered:

http://splunk-base.splunk.com/answers/62315/cross-site-scripting-xss-vulnerability-in-splunk-40-thro...

Recommendation/Mitigation is to upgrade to at least 4.3.6 or 5.0.3

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

SPL-59895 (CVE-2012-6447 reserved) is for 5.0.0-5.0.2.

The same issue in 4.3.0-4.3.5 is tracked as SPL-60629 (CVE-2013-2766) and was
fixed in 4.3.6 as announced here:

http://www.splunk.com/view/SP-CAAAHSQ

This was already answered:

http://splunk-base.splunk.com/answers/62315/cross-site-scripting-xss-vulnerability-in-splunk-40-thro...

Recommendation/Mitigation is to upgrade to at least 4.3.6 or 5.0.3

Hajime
Path Finder

Thank you for answering my questions.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...