CVE-2022-32151 is a critical vulnerability affecting Splunk Enterprise versions prior to 9.0 and Splunk Cloud Platform versions prior to 8.2.2203. It stems from the httplib and urllib Python libraries failing to validate server certificates by default, leading to a lack of proper TLS certificate hostname validation. This allows for potential man-in-the-middle attacks, enabling an unauthenticated attacker to intercept and compromise sensitive data with high confidentiality and integrity impact. While rated 9.1 Critical, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.0CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
< 8.2.2203CPE matchmatch criteria | cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.