CVE-2022-32158: Splunk Enterprise deployment servers allow client publishing of forwarder bundles
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32158?
CVE-2022-32158 is a vulnerability in Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 that allows clients to deploy forwarder bundles to other deployment clients, potentially leading to the execution of arbitrary code on all affected clients.
What is the severity of CVE-2022-32158?
CVE-2022-32158 is considered a critical vulnerability with a severity value of 10.
How does CVE-2022-32158 affect Splunk Enterprise?
CVE-2022-32158 affects Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0.
How can an attacker exploit CVE-2022-32158?
An attacker who compromised a Universal Forwarder endpoint could exploit CVE-2022-32158 to execute arbitrary code on all affected deployment clients.
Are there any fixes or updates available for CVE-2022-32158?
Yes, updates are available to address CVE-2022-32158. Splunk recommends upgrading to version 8.1.10.1, 8.2.6.1, or 9.0 to mitigate this vulnerability.