CVE-2022-32154: Risky commands warnings in Splunk Enterprise Dashboards
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/SPLsafeguards#Newcapabilitiescanlimitaccesstosomecustomandpotentiallyriskycommands) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32154?
CVE-2022-32154 is a vulnerability in Splunk Enterprise versions before 9.0 that allows an attacker to inject risky search commands into a form token, bypassing SPL safeguards.
What is the severity of CVE-2022-32154?
The severity of CVE-2022-32154 is high with a CVSS score of 8.1.
Which versions of Splunk Enterprise are affected by CVE-2022-32154?
Splunk Enterprise versions before 9.0 are affected by CVE-2022-32154.
How can an attacker exploit CVE-2022-32154?
An attacker can exploit CVE-2022-32154 by injecting risky search commands into a form token used in a query in a cross-origin request.
How can I mitigate CVE-2022-32154?
To mitigate CVE-2022-32154, it is recommended to upgrade to Splunk Enterprise version 9.0 or later.