В версиях Splunk Enterprise Security ниже 8.6.1 пользователь с ролью ess_analyst Splunk Enterprise Security может изменять макросы поиска User and Entity Behavior Analytics (UEBA), которые планируют поиски, выполняемые с разрешениями администратора, обеспечивая доступ ко всем соответствующим данным и целостности системы посредством этих поисков. Уязвимость возможна, поскольку метаданные приложения UEBA предоставляют ролям аналитиков доступ на запись к макросам поиска, которые должны быть доступны для записи только ролям администраторов. Для получения дополнительной информации см. «Пользователи и роли для Splunk Enterprise Security» (https://help.splunk.com/en/splunk-enterprise-security-8/install/8.4/installation/users-and-roles-for-splunk-enterprise-security) и «Роли и объекты знаний в UEBA для Splunk Enterprise Security». (https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.5/user-and-entity-behavior-analytics/roles-and-knowledge-objects-in-ueba-for-splunk-enterprise-security) в документации Splunk.
Показать оригинальное описание (EN)
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through those searches. The vulnerability is possible because the UEBA app metadata grants analyst roles write access to search macros that should be writable only by administrator roles. For more information see Users and roles for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/install/8.4/installation/users-and-roles-for-splunk-enterprise-security) and Roles and knowledge objects in UEBA for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.5/user-and-entity-behavior-analytics/roles-and-knowledge-objects-in-ueba-for-splunk-enterprise-security) in the Splunk documentation.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 1
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Splunk Enterprise_Security
cpe:2.3:a:splunk:enterprise_security:*:*:*:*:*:*:*:*
|
— |
8.6.1
|