Impact
The AWS IAM app for Splunk SOAR contains an unmasked credentials parameter in actions that are run by users with permission to execute them. In versions older than 2.1.9, the app does not mark this parameter as a password and displays it in cleartext in the user interface. An attacker who can trigger such an action can read the embedded AWS credentials from the UI, potentially giving them unauthorized access to AWS resources. The vulnerability results in sensitive data exposure but does not provide a pathway to arbitrary code execution or denial of service.
Affected Systems
The affected software is the Splunk AWS IAM app for Splunk SOAR. Any installation of the app with a version earlier than 2.1.9 is vulnerable. The remedy requires Splunk SOAR version 8.6.0 or later. Users of the older app versions should upgrade to the fixed release to block the disclosure.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the vulnerability is not listed in CISA's KEV catalog. The EPSS is not available, so the exact exploitation likelihood is unknown. The attack vector is limited to users who have rights to run actions; they can trigger a vulnerable action and view its output in the interface. While the exposure of credentials is serious, the requirement to log in and have action execution rights reduces the attack surface to authorized users or insiders.
OpenCVE Enrichment