CVE-2022-43568: Reflected Cross-Site Scripting via the radio template in Splunk Enterprise
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when outputmode=radio.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.0.2
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-43568.
What is the severity of CVE-2022-43568?
The severity of CVE-2022-43568 is high with a severity value of 6.1.
Which versions of Splunk Enterprise are affected by CVE-2022-43568?
Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2 are affected by CVE-2022-43568.
How can CVE-2022-43568 be exploited?
CVE-2022-43568 can be exploited through a View that allows for a Reflected Cross Site Scripting via JSON in a query parameter.
Are there any references available for CVE-2022-43568?
Yes, you can find more information about CVE-2022-43568 at the following references: [Link 1](https://research.splunk.com/application/d532d105-c63f-4049-a8c4-e249127ca425/) and [Link 2](https://www.splunk.com/en_us/product-security/announcements/svd-2022-1108.html).