CyberRota Analysis
AI-GeneratedIn Splunk SOAR versions prior to 8.6.0, users with the OnPrem Broker role can exploit a vulnerability that allows them to write files outside the designated Automation Broker log directory due to improper handling of crafted filename inputs. This could lead to unauthorized file access or manipulation, posing a risk to system integrity. Organizations using affected versions of Splunk SOAR should prioritize patching to mitigate potential security risks associated with this vulnerability.
Original NVD Description
In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and permissions in Splunk SOAR (Cloud) (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)