Impact
A low‑privileged user lacking admin or power roles can retrieve encrypted credential hashes stored by Splunk via the /servicesNS/-/-/storage/passwords REST endpoint, because the |rest SPL command includes the encr_password field in its output. This results in the accidental disclosure of sensitive credential information (CWE‑200).
Affected Systems
The issue affects Splunk Enterprise releases below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform releases below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate. The EPSS score is below 1 %, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it by running a |rest command in the Splunk query DSL when logged into the platform, which is possible for any user without admin or power privileges, making the attack path local to the Splunk environment and dependent on legitimate user access. No privileged escalation is required, but the exposed credential hashes could be leveraged in further attacks if harvested.
OpenCVE Enrichment