Splunk Product Security Update Advisory (CVE-2024-53247)
Overview
We have released security updates to fix vulnerabilities in Splunk products. affected product users are advised to update to the latest version.
Affected Products
CVE-2024-53247
- Splunk Enterprise Version: 9.3.1
- Splunk Enterprise version: 9.2.3
- Splunk Enterprise Versions: 9.1.0 (inclusive) to 9.1.6 (inclusive)
- Splunk Secure Gateway version: ~ 3.7.13 (excluded)
- Splunk Secure Gateway version: ~ 3.4.261 (excluded)
Resolved Vulnerabilities
Vulnerability that allows a low privileged user without an “admin” or “power” Splunk role to perform remote code execution (RCE) (CVE-2024-53247)
Vulnerability Patches
vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-53247
- Splunk Enterprise version: 9.3.2
- Splunk Enterprise version: 9.2.4
- Splunk Enterprise version: 9.1.7
- Splunk Secure Gateway version: 3.7.13
- Splunk Secure Gateway version: 3.4.261
references
[1] CVE-2024-53247 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-53247
[2] Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway app