CVE-2017-17067: Critical severity Splunk splunk vulnerability
Splunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the SAML authType is enabled, mishandles SAML, which allows remote attackers to bypass intended access restrictions or conduct impersonation attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17067?
CVE-2017-17067 has a critical severity rating of 9.8.
How do I fix CVE-2017-17067?
To fix CVE-2017-17067, upgrade Splunk Enterprise to a version greater than 7.0.0.1, 6.6.3.2, 6.5.6, 6.4.9, or 6.3.12.
What types of attacks can CVE-2017-17067 allow?
CVE-2017-17067 can allow remote attackers to bypass access restrictions or conduct impersonation attacks.
Which versions of Splunk are affected by CVE-2017-17067?
CVE-2017-17067 affects Splunk Enterprise versions 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12.
What authentication method is mishandled in CVE-2017-17067?
CVE-2017-17067 mishandles the SAML authentication method when the SAML authType is enabled.