CVE-2010-3323: Medium severity Splunk splunk vulnerability
Published Sep 14, 2010
·Updated
Splunk 4.0.0 through 4.1.4 allows remote attackers to conduct session hijacking attacks and obtain the splunkd session key via vectors related to the SPLUNKDSESSIONKEY parameter.
Affected Software
17 affected components
Splunk splunk=4.0
Splunk splunk=4.0.1
Splunk splunk=4.0.2
Splunk splunk=4.0.3
Splunk splunk=4.0.4
Splunk splunk=4.0.5
Splunk splunk=4.0.6
Splunk splunk=4.0.7
Splunk splunk=4.0.8
Splunk splunk=4.0.9
Splunk splunk=4.0.10
Splunk splunk=4.0.11
Splunk splunk=4.1
Splunk splunk=4.1.1
Splunk splunk=4.1.2
Splunk splunk=4.1.3
Splunk splunk=4.1.4
Remediation
Patch Available
Event History
Sep 14, 2010
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-3323?
CVE-2010-3323 is rated as medium severity due to its potential for session hijacking.
2
How do I fix CVE-2010-3323?
To mitigate CVE-2010-3323, upgrade to a patched version of Splunk that is not affected, preferably 4.1.5 or higher.
3
What versions of Splunk are affected by CVE-2010-3323?
CVE-2010-3323 affects Splunk versions 4.0.0 through 4.1.4.
4
Can CVE-2010-3323 be exploited remotely?
Yes, CVE-2010-3323 can be exploited remotely by attackers to hijack sessions.
5
What is the primary attack vector for CVE-2010-3323?
The primary attack vector for CVE-2010-3323 involves manipulating the SPLUNKD_SESSION_KEY parameter.