Impact
In versions of the Azure AD Graph app for Splunk SOAR prior to 2.5.3 the reset password action displays the generated temporary password unmasked in the user interface. A user who has a role that permits running actions can trigger this reset and directly see a clear‑text password, exposing sensitive credentials to anyone who can view the action output. The disclosure is limited to passwords generated by the application but can compromise account security.
Affected Systems
Splunk’s Azure AD Graph app for Splunk SOAR, versions earlier than 2.5.3, on any deployment running Splunk SOAR. The fix is available only in app versions that require Splunk SOAR 8.6.0 or newer.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating moderate risk. EPSS information is not available, so the likelihood of automated exploitation is unknown, but the attack requires a legitimate user with action‑execution privileges, meaning it is an internal risk. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation yet. Attackers must possess role permissions to run actions; no external attacker can trigger the disclosure merely by sending a request.
OpenCVE Enrichment