Data: CASIE
Negative Trigger
a
slip
in
its
JavaScript
implementation
that
leaks
Attack.Databreach
user
information
.
The
advisory
at
Full
Disclosure
explains
that
the leak
Attack.Databreach
happens
if
an
attacker
tricks
Attack.Phishing
an
authenticated
user
into
visiting
a
malicious
Web
page
.
It
only
leaks
Attack.Databreach
the
username
,
and
whether
or
not
that
user
has
enabled
remote
access
;
but
this
would
provide
enough
for
an
attacker
to
try
follow-up phishing attacks
Attack.Phishing
to
try
and
get
the
user
's
credentials
.
The
bug
,
the
advisory
says
Vulnerability-related.DiscoverVulnerability
,
is
how
Splunk
used
Object
prototypes
in
JavaScript
.
Here
's
the
proof-of-concept
JavaScript
from
the
advisory
:
The
issue
affects
Vulnerability-related.DiscoverVulnerability
Splunk
Enterprise
versions
6.5.x
before
6.5.3
,
6.4.x
before
6.4.6
,
6.3.x
before
6.3.10
,
6.2.x
before
6.2.13.1
,
6.1.x
before
6.1.13
,
6.0.x
before
6.0.14
,
5.0.x
before
5.0.18
and
Splunk
Light
before
6.5.2
,
and
the
company
has issued
Vulnerability-related.PatchVulnerability
patches
for
all
versions