CVE-2022-43571: Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.0.2
Event History
Frequently Asked Questions
What is CVE-2022-43571?
CVE-2022-43571 is a vulnerability in Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, where an authenticated user can execute arbitrary code through the dashboard PDF generation component.
How severe is CVE-2022-43571?
CVE-2022-43571 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2022-43571?
CVE-2022-43571 affects Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, as well as Splunk Cloud Platform up to version 9.0.2209.
How can an authenticated user exploit CVE-2022-43571?
An authenticated user can exploit CVE-2022-43571 by executing arbitrary code through the dashboard PDF generation component in affected versions of Splunk Enterprise.
Are there any fixes or patches available for CVE-2022-43571?
Yes, for CVE-2022-43571, it is recommended to upgrade Splunk Enterprise to version 8.2.9, 8.1.12, or 9.0.2, and upgrade Splunk Cloud Platform to a version higher than 9.0.2209.