CyberRota Analysis
AI-GeneratedThe Splunk On-Call (VictorOps) app versions prior to 1.0.43 are vulnerable as they allow non-admin users to access a partially masked API key stored in the App Key Value Store. This exposure could lead to unauthorized access to sensitive functionalities or data associated with the API. Organizations using affected versions of the app should prioritize updating to mitigate potential security risks.
Original NVD Description
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)