Splunk disclosed that Splunk Enterprise deployment servers before version 9.0 allowed unauthenticated downloading of forwarder bundles, a weakness tracked as CVE-2022-32157. The issue could expose sensitive configuration data contained in deployment bundles and potentially aid follow-on activity such as lateral movement, while Splunk Cloud Platform was not affected because it does not use deployment servers. Splunk said Universal Forwarders were not directly vulnerable, but customers needed to upgrade both deployment servers and managed forwarders to version 9.0 or later and enable authentication between servers and clients to fully remediate the risk.
Splunk later published a hunting analytic designed to detect suspicious bundle downloads through PackageDownloadRestHandler logs, helping defenders identify cases where unauthorized clients may have retrieved deployment content. That detection has since been removed and deprecated from Splunk Threat Research content because the associated vulnerabilities were patched in current releases, and Splunk said it had no evidence of external exploitation at the time of disclosure. The company noted that impact varies with the sensitivity of the bundle contents, ranging from informational to medium severity in lower-risk environments.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Splunk removed the hunting detection "Splunk Process Injection Forwarder Bundle Downloads" from its Threat Research content library in version 5.6.0, stating it is no longer maintained or supported. Splunk said the detection was deprecated because the associated CVEs, including CVE-2022-32157, had been patched in the latest Splunk release.
On 2022-07-18, Splunk's SVD-2022-0607 advisory changelog says it added Components in the Product Status table, Severity Considerations, and acknowledgments for Paul Schultze and Martin Müller. The advisory covers a flaw in Splunk Enterprise deployment servers before 9.0 that allows unauthenticated downloading of forwarder bundles.
A Splunk security_content workbook file named splunk_psa_0622.json was published in the referenced GitHub repository. The reference provides no further event details beyond the file's publication.
Splunk disclosed that Splunk Enterprise deployment servers before version 9.0 permit unauthenticated forwarder bundle downloads and identified Splunk Enterprise 9.0.0 as the fixed version. Splunk instructed customers to upgrade deployment servers and managed Universal Forwarders to 9.0 or later and enable authentication between deployment servers and clients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcesplunk.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.