CyberRota Analysis
AI-GeneratedSplunk SOAR versions prior to 8.6.0 are vulnerable to an information disclosure issue where authenticated users can exploit REST API filtering on playbook runs to retrieve session tokens, potentially compromising all accessible data. This vulnerability arises from the failure to restrict API filters from exposing hidden response values. Organizations using affected Splunk SOAR versions should prioritize patching to mitigate the risk of unauthorized data access.
Original NVD Description
In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/run-playbook-endpoints/rest-run-playbook) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)