CVE-2021-31559: S2S TcpToken authentication bypass
Published May 6, 2022
·Updated
A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders.
Affected Software
2 affected components
Splunk splunk>=8.1.0<8.1.5
Splunk splunk=8.2.0
Event History
May 6, 2022
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-31559?
CVE-2021-31559 has been classified as a high severity vulnerability.
2
How do I fix CVE-2021-31559?
To fix CVE-2021-31559, upgrade Splunk Enterprise to version 8.1.5 or 8.2.1 or later.
3
Which Splunk Enterprise versions are affected by CVE-2021-31559?
CVE-2021-31559 affects Splunk Enterprise versions before 8.1.5 and 8.2 before 8.2.1.
4
What impact does CVE-2021-31559 have on Splunk Indexers?
CVE-2021-31559 allows arbitrary events to be written to an index when S2S TCP Token authentication is bypassed.
5
Are Universal Forwarders impacted by CVE-2021-31559?
No, Universal Forwarders are not impacted by CVE-2021-31559.