Splunk Product Security Update Advisory (CVE-2024-53247)

Overview

 

We have released security updates to fix vulnerabilities in Splunk products. affected product users are advised to update to the latest version.
 

 

Affected Products

 

CVE-2024-53247

  • Splunk Enterprise Version: 9.3.1
  • Splunk Enterprise version: 9.2.3
  • Splunk Enterprise Versions: 9.1.0 (inclusive) to 9.1.6 (inclusive)

 

  • Splunk Secure Gateway version: ~ 3.7.13 (excluded)
  • Splunk Secure Gateway version: ~ 3.4.261 (excluded)

 

 

Resolved Vulnerabilities

 

Vulnerability that allows a low privileged user without an “admin” or “power” Splunk role to perform remote code execution (RCE) (CVE-2024-53247)

 

Vulnerability Patches

vulnerability patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-53247

  • Splunk Enterprise version: 9.3.2
  • Splunk Enterprise version: 9.2.4
  • Splunk Enterprise version: 9.1.7

 

  • Splunk Secure Gateway version: 3.7.13
  • Splunk Secure Gateway version: 3.4.261

 

 

references

 

[1] CVE-2024-53247 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-53247

[2] Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway app

https://advisory.splunk.com/advisories/SVD-2024-1205