CVE-2018-7429: Input Validation
Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to cause a denial of service via a malformed HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7429?
CVE-2018-7429 is classified as a denial of service vulnerability affecting multiple versions of Splunk.
How do I fix CVE-2018-7429?
To fix CVE-2018-7429, upgrade to Splunk Enterprise version 6.2.14 or later, 6.3.11 or later, 6.4.8 or later, or install Splunk Light version 6.5.0 or later.
What causes the vulnerability CVE-2018-7429?
CVE-2018-7429 is caused by Splunkd allowing remote attackers to send malformed HTTP requests which trigger a denial of service.
Which versions of Splunk are affected by CVE-2018-7429?
CVE-2018-7429 affects Splunk Enterprise versions 6.2.x prior to 6.2.14, 6.3.x prior to 6.3.11, 6.4.x prior to 6.4.8, and Splunk Light prior to 6.5.0.
Is CVE-2018-7429 exploitable remotely?
Yes, CVE-2018-7429 can be exploited remotely by attackers to cause a denial of service.