Quantcast
Channel: SANS Internet Storm Center, InfoCON: green
Viewing all articles
Browse latest Browse all 8246

Reflected XSS in Splunk Web Affecting Version 4.0 to 4.3, (Wed, Mar 7th)

$
0
0
A vulnerability has be found in Splunk 4.0 - 4.3 that allows partial confidentiality and integrity violation, when a user click on a specifically crafted link that can disclose sensitive information to the attacker. Splunk recommend consumers upgrade to version 4.3.1 and to follow its hardening standard [3] to mitigate the risk of exploitation.
[1] http://www.splunk.com/view/SP-CAAAGTK

[2] http://www.splunk.com/download

[3] http://docs.splunk.com/Documentation/Splunk/latest/Admin/Hardeningstandards
-----------
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Viewing all articles
Browse latest Browse all 8246

Trending Articles