Impact
The CrowdStrike OAuth API app for Splunk SOAR, versions before 5.1.3, does not mask the document_password field in the detonate file or detonate URL actions. When an authorized user runs these actions, the password is displayed in clear text in the UI, allowing disclosure of confidential credential data. This flaw is identified as an information‑disclosure weakness (CWE‑312).
Affected Systems
Affected versions are all releases of the app before 5.1.3 that run on Splunk SOAR. The fixed app requires Splunk SOAR 8.6.0 or newer. Users with roles that can execute actions against the app, such as analysts or administrators, are potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available, so the probability of threat currently is unconstrained. The vulnerability is not listed in the CISA KEV catalog. The only known attack path is an internal user with sufficient action‑execution rights. An attacker who can run the detonate actions can view the document password in the interface, leaking sensitive credential information. The flaw is mitigated by applying the fixed app version or disabling the app if upgrading is not possible.
OpenCVE Enrichment