CVE-2024-22164: Denial of Service of an Investigation in Splunk Enterprise Security through Investigation attachments
In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterprise Security (ES)to a version that resolves this vulnerability.Fixed in 7.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22164?
CVE-2024-22164 is classified as a denial of service (DoS) vulnerability affecting Splunk Enterprise Security versions below 7.1.2.
How do I fix CVE-2024-22164?
To fix CVE-2024-22164, upgrade to Splunk Enterprise Security version 7.1.2 or later.
What versions are affected by CVE-2024-22164?
CVE-2024-22164 affects all versions of Splunk Enterprise Security below 7.1.2.
What type of attack can be performed using CVE-2024-22164?
An attacker can perform a denial of service (DoS) attack through malicious investigation attachments.
What should I do if I cannot upgrade to fix CVE-2024-22164?
If upgrading is not possible, consider implementing strict controls on attachment sizes and monitoring for unusual activity.