CVE-2022-43567: Remote Code Execution via the Splunk Secure Gateway application Mobile Alerts feature
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterprise / Splunk Secure Gateway (Mobile Alerts feature)to a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
Splunk Enterprise / Splunk Secure Gateway (Mobile Alerts feature)to a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
Splunk Enterprise / Splunk Secure Gateway (Mobile Alerts feature)to a version that resolves this vulnerability.Fixed in 9.0.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this Splunk Enterprise vulnerability?
The vulnerability ID is CVE-2022-43567.
What is the severity level of CVE-2022-43567?
The severity level of CVE-2022-43567 is high.
How can an authenticated user exploit CVE-2022-43567?
An authenticated user can exploit CVE-2022-43567 by running arbitrary operating system commands remotely through specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.
Which versions of Splunk Enterprise are affected by CVE-2022-43567?
Versions below 8.2.9, 8.1.12, and 9.0.2 of Splunk Enterprise are affected by CVE-2022-43567.
How can I fix CVE-2022-43567 in Splunk Enterprise?
To fix CVE-2022-43567 in Splunk Enterprise, you should update to version 8.2.9, 8.1.12, or 9.0.2 of Splunk Enterprise.