CVE-2022-43562: Host Header Injection in Splunk Enterprise
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
splunk/splunk-enterpriseto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
splunk/splunk-enterpriseto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
splunk/splunk-enterpriseto a version that resolves this vulnerability.Fixed in 9.0.2
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-43562.
What is the severity of CVE-2022-43562?
The severity of CVE-2022-43562 is medium (5.4).
Which versions of Splunk Enterprise are affected by CVE-2022-43562?
Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2 are affected by CVE-2022-43562.
What is the impact of CVE-2022-43562?
CVE-2022-43562 could allow a remote authenticated user to conduct various attacks against the system, including cross-site scripting and cache poisoning.
Where can I find more information about CVE-2022-43562?
More information about CVE-2022-43562 can be found at the [Splunk Product Security Announcements page](https://www.splunk.com/en_us/product-security/announcements/svd-2022-1102.html).