mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
44 lines
1.6 KiB
YAML
44 lines
1.6 KiB
YAML
name: Splunk Enterprise Vulnerability
|
|
id: 4e692b96-de2d-4bd1-9105-37e2368a8db1
|
|
version: 1
|
|
date: '2017-09-19'
|
|
description: Keeping your Splunk deployment up to date is critical and may help you
|
|
reduce the risk of CVE-2016-4859, an open-redirection vulnerability within some
|
|
older versions of Splunk Enterprise. The detection search will help ensure that
|
|
users are being properly authenticated and not being redirected to malicious domains.
|
|
narrative: 'This Analytic Story is associated with CVE-2016-4859, an open-redirect
|
|
vulnerability in the following versions of Splunk Enterprise:\
|
|
|
|
\
|
|
|
|
1. Splunk Enterprise 6.4.x, prior to 6.4.3\
|
|
|
|
1. Splunk Enterprise 6.3.x, prior to 6.3.6\
|
|
|
|
1. Splunk Enterprise 6.2.x, prior to 6.2.10\
|
|
|
|
1. Splunk Enterprise 6.1.x, prior to 6.1.11\
|
|
|
|
1. Splunk Enterprise 6.0.x, prior to 6.0.12\
|
|
|
|
1. Splunk Enterprise 5.0.x, prior to 5.0.16\
|
|
|
|
1. Splunk Light, prior to 6.4.3CVE-2016-4859 allows attackers to redirect users
|
|
to arbitrary web sites and conduct phishing attacks via unspecified vectors. (Credit:
|
|
Noriaki Iwasaki, Cyber Defense Institute, Inc.).\
|
|
|
|
It is important to ensure that your Splunk deployment is being kept up to date and
|
|
is properly configured. This detection search allows analysts to monitor internal
|
|
logs to ensure users are properly authenticated and cannot be redirected to any
|
|
malicious third-party websites.'
|
|
author: Bhavin Patel, Splunk
|
|
type: ESCU
|
|
references:
|
|
- http://www.splunk.com/view/SP-CAAAPQ6#announce
|
|
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4859
|
|
tags:
|
|
analytics_story: Splunk Enterprise Vulnerability
|
|
usecase: Security Monitoring
|
|
category:
|
|
- Vulnerability
|