CVE-2022-43561: Persistent Cross-Site Scripting in “Save Table” Dialog in Splunk Enterprise
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.0.2
Event History
Frequently Asked Questions
What is the vulnerability ID of this Splunk Enterprise vulnerability?
The vulnerability ID of this Splunk Enterprise vulnerability is CVE-2022-43561.
What is the severity of CVE-2022-43561?
The severity of CVE-2022-43561 is medium.
Which versions of Splunk Enterprise are affected?
Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2 are affected.
How can a remote user exploit this vulnerability?
A remote user with the "power" role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS) attacks.
Are instances with Splunk Cloud Platform affected by this vulnerability?
Instances with Splunk Cloud Platform up to version 9.0.2208 are affected by this vulnerability.
How can I fix this vulnerability?
Upgrade to Splunk Enterprise version 8.1.12, 8.2.9, or 9.0.2 to fix this vulnerability.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following URLs: [Splunk Research](https://research.splunk.com/application/a974d1ee-ddca-4837-b6ad-d55a8a239c20/) and [Splunk Product Security](https://www.splunk.com/en_us/product-security/announcements/svd-2022-1101.html).