CVE-2023-22942: Cross-Site Request Forgery in the ‘ssg/kvstore_client’ REST Endpoint in Splunk Enterprise
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a cross-site request forgery in the Splunk Secure Gateway (SSG) app in the ‘kvstoreclient’ REST endpoint lets a potential attacker update SSG App Key Value Store (KV store) collections using an HTTP GET request. SSG is a Splunk-built app that comes with Splunk Enterprise. The vulnerability affects instances with SSG and Splunk Web enabled.
Other sources
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a cross-site request forgery in the Splunk Secure Gateway (SSG) app in the ‘kvstoreclient’ REST endpoint lets a potential attacker update SSG KV store collections using an HTTP GET request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22942.
What is the title of the vulnerability?
The title of the vulnerability is Cross-Site Request Forgery in the 'ssg/kvstore_client' REST Endpoint in Splunk Enterprise.
What is the severity of CVE-2023-22942?
The severity of CVE-2023-22942 is medium with a CVSS score of 5.4.
Which versions of Splunk Enterprise are affected by CVE-2023-22942?
Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4 are affected by CVE-2023-22942.
How can I fix CVE-2023-22942?
To fix CVE-2023-22942, it is recommended to upgrade Splunk Enterprise to version 8.1.13, 8.2.10, or 9.0.4 or later.