CyberRota Analysis
AI-GeneratedThe Splunk AI Toolkit versions prior to 6.0.0 are vulnerable, allowing non-admin users to access predictable or hard-coded credentials for connected container services. This could lead to unauthorized access and potential exploitation of those services. Organizations using affected versions of the Splunk AI Toolkit should prioritize this vulnerability to mitigate risks associated with credential exposure.
Original NVD Description
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container services using predictable or hard-coded default values. For more information see Connections tab in the AI Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.7.2/ai-toolkit-commands-macros-and-visualizations/connections-tab-in-the-ai-toolkit) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)