CVE-2022-37439: Malformed ZIP file crashes Universal Forwarders and Splunk Enterprise through file monitoring input
In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37439?
The severity of CVE-2022-37439 is medium with a severity value of 5.5.
What is the affected software for CVE-2022-37439?
The affected software for CVE-2022-37439 is Splunk Enterprise and Universal Forwarder versions 8.1.0 to 8.1.11 and 8.2.0 to 8.2.7.1.
How does CVE-2022-37439 impact Splunk Enterprise and Universal Forwarder?
CVE-2022-37439 can result in a crash of the application when indexing a specially crafted ZIP file using the file monitoring input.
How can I fix CVE-2022-37439?
To fix CVE-2022-37439, upgrade Splunk Enterprise and Universal Forwarder to versions 8.1.12 or 8.2.7.2 or later.
Where can I find more information about CVE-2022-37439?
You can find more information about CVE-2022-37439 on the Splunk Research Portal and the Splunk Product Security Announcements page.