Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream
Vulnerability Description
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32713
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Ben Leonard-Lagarde & Lucas Fedyniak-Hopes (Modux)
More from Splunk
View All →Affected Vendor
Splunk
View all reports →