Impact
In earlier releases of the AD LDAP app for Splunk SOAR, the connector writes its entire process environment to a persistent debug log when an action is invoked. A user with any role that permits action execution can trigger this behavior, thereby exposing sensitive credentials and configuration data in plaintext log files. The weakness is identified as CWE‑532, illustrating improper exposure of system information. The consequence is a confidentiality breach that can lead to credential compromise for downstream services connected through the LDAP connector.
Affected Systems
The vulnerability affects Splunk SOAR installations that include the AD LDAP app with a version earlier than 2.3.8. The remediation requires the fixed connector to be deployed on Splunk SOAR 8.6.0 or later; therefore any SOAR instance using an older core version is implicitly impacted if the app is present. Users should verify whether their environment hosts the legacy app and has a sufficient SOAR core to support the update.
Risk and Exploitability
The CVSS score of 5 points classifies this flaw as medium severity. EPSS information is not available, so the likelihood of exploitation cannot be precisely quantified. The vulnerability is not listed in KEV, indicating no publicly reported exploitation yet. The attack vector is internal: an authenticated user possessing action‑execution rights can trigger the environment dump. This requirement limits the exposure to trusted roles, but the impact of credential exposure remains significant.
OpenCVE Enrichment