First published: Fri May 06 2022(Updated: )
The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Enterprise versions before 8.1.4. The Monitoring Console app is a bundled app included in Splunk Enterprise, not for download on SplunkBase, and not installed on Splunk Cloud Platform instances. Note that the Cloud Monitoring Console is not impacted.
Credit: prodsec@splunk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Splunk | >=8.1.0<8.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27183 has a critical severity level due to its potential for reflected Cross-Site Scripting attacks.
To resolve CVE-2022-27183, upgrade Splunk Enterprise to version 8.1.4 or later.
CVE-2022-27183 affects Splunk Enterprise versions prior to 8.1.4.
CVE-2022-27183 is a reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2022-27183 is found within the Monitoring Console app configured in Distributed mode.