CVE-2023-32709
In Splunk Enterprise versions below 9.0.5, 8.2.11. and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user who holds the ‘user’ role can see the hashed version of the initial user name and password for the Splunk…
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
In Splunk Enterprise versions below 9.0.5, 8.2.11. and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user who holds the ‘user’ role can see the hashed version of the initial user name and password for the Splunk instance by using the ‘rest’ SPL command against the ‘conf-user-seed’ REST endpoint.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- splunk/splunk · splunk/splunk cloud platform
- Source
- prodsec@splunk.com
References
- https://advisory.splunk.com/advisories/SVD-2023-0604Vendor Advisory
- https://research.splunk.com/application/a1be424d-e59c-4583-b6f9-2dcc23be4875/Vendor Advisory
- https://advisory.splunk.com/advisories/SVD-2023-0604Vendor Advisory
- https://research.splunk.com/application/a1be424d-e59c-4583-b6f9-2dcc23be4875/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.