vendor:
Splunk Enterprise
by:
John Page AKA hyp3rlinx
3,5
CVSS
LOW
Javascript (JSON) Information Theft
200
CWE
Product Name: Splunk Enterprise
Affected Version From: 6.5.x, 6.4.x, 6.3.x, 6.2.x, 6.1.x, 6.0.x, 5.0.x, Splunk Light
Affected Version To: 6.5.2, 6.4.5, 6.3.9, 6.2.12.1, 6.1.12, 6.0.13, 5.0.17, Splunk Light 6.5.2
Patch Exists: YES
Related CWE: CVE-2017-5607
CPE: a:splunk:splunk_enterprise
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2017
Javascript (JSON) Information Theft
Attackers can siphon information from Splunk Enterprise if an authenticated Splunk user visits a malicious webpage. Some useful data gained is the currently logged in username and if remote user setting is enabled. After, the username can be use to Phish or Brute Force Splunk Enterprise login. Additional information stolen may aid in furthering attacks. Root cause is the global Window JS variable assignment of config?autoload=1 '$C'.
Mitigation:
Upgrade to Splunk Enterprise 6.5.3, 6.4.6, 6.3.10, 6.2.13.1, 6.1.13, 6.0.14, 5.0.18 or Splunk Light 6.5.2. Alternatively, disable remote user setting.