First published: Wed Jun 15 2022(Updated: )
Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.
Credit: prodsec@splunk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Splunk Splunk | <9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32158 is a vulnerability in Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 that allows clients to deploy forwarder bundles to other deployment clients, potentially leading to the execution of arbitrary code on all affected clients.
CVE-2022-32158 is considered a critical vulnerability with a severity value of 10.
CVE-2022-32158 affects Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0.
An attacker who compromised a Universal Forwarder endpoint could exploit CVE-2022-32158 to execute arbitrary code on all affected deployment clients.
Yes, updates are available to address CVE-2022-32158. Splunk recommends upgrading to version 8.1.10.1, 8.2.6.1, or 9.0 to mitigate this vulnerability.