Sunday, April 27, 2025
HomeCVE/vulnerabilitySplunk RCE Vulnerability Let Attackers Execute Remote Code

Splunk RCE Vulnerability Let Attackers Execute Remote Code

Published on

SIEM as a Service

Follow Us on Google News

Splunk, the data analysis and monitoring platform, is grappling with a Remote Code Execution (RCE) vulnerability.

This flaw, identified as CVE-2024-53247, affects several versions of Splunk Enterprise and the Splunk Secure Gateway app on the Splunk Cloud Platform.

The vulnerability is rated with a CVSSv3.1 score of 8.8, indicating a high severity level that poses a serious risk to organizations relying on these services.

- Advertisement - Google News

Vulnerability Details

The RCE vulnerability arises from the unsafe deserialization of untrusted data, traced back to insecure usage of the jsonpickle Python library.

This deserialization flaw allows a low-privileged user, who does not possess “admin” or “power” roles, to execute arbitrary code on the affected systems.

Notably, this issue impacts Splunk Enterprise versions before 9.3.2, 9.2.4, and 9.1.7, as well as Splunk Secure Gateway versions below 3.2.461 and 3.7.13.

2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide

Affected Products and Versions

  • Splunk Enterprise: Versions 9.3.1 and below, 9.2.3 and below, 9.1.0 to 9.1.6.
  • Splunk Secure Gateway App: Versions below 3.7.13 and 3.4.261.

To counter this vulnerability, Splunk has advised users to upgrade to the latest secure versions: 9.3.2, 9.2.4, and 9.1.7 for Splunk Enterprise, and 3.7.13 or 3.4.261 for the Splunk Secure Gateway app.

Additionally, Splunk is proactively monitoring and patching instances on the Splunk Cloud Platform to mitigate potential risks.

As an immediate workaround, Splunk recommends disabling the Splunk Secure Gateway app, particularly if the functionalities of Splunk Mobile, Spacebridge, and Mission Control are not in use.

Administrators should manage app and add-on objects to ensure the system’s integrity and security.

This vulnerability underscores the critical importance of keeping enterprise software updated and securely configured, especially when handling sensitive data.

Organizations using Splunk must act promptly to apply the necessary updates and consider implementing additional security measures to prevent exploitation.

Splunk’s swift response and transparency in addressing this issue are commendable, yet this incident serves as a reminder of the constant vigilance needed in cybersecurity.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...