CVE-2022-43565: Risky command safeguards bypass via ‘tstats command JSON in Splunk Enterprise
In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.1.12
Event History
Frequently Asked Questions
What is the vulnerability ID for this Splunk Enterprise vulnerability?
The vulnerability ID for this Splunk Enterprise vulnerability is CVE-2022-43565.
What is the severity of CVE-2022-43565?
The severity of CVE-2022-43565 is high.
Which versions of Splunk Enterprise are affected by CVE-2022-43565?
Splunk Enterprise versions below 8.2.9 and 8.1.12 are affected by CVE-2022-43565.
How does CVE-2022-43565 allow an attacker to bypass SPL safeguards?
CVE-2022-43565 allows an attacker to bypass SPL safeguards by exploiting the way the 'tstats' command handles JSON.
Where can I find more information about CVE-2022-43565?
You can find more information about CVE-2022-43565 at https://www.splunk.com/en_us/product-security/announcements/svd-2022-1105.html.