Impact
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, the reset password action exposes the temporary password in cleartext because the temp_password parameter is not masked in the user interface. This flaw allows a user with a role that can run actions to view a sensitive password, compromising confidentiality of account credentials. The weakness is an instance of insecure handling of sensitive information.
Affected Systems
The affected product is the MS Graph for Active Directory app for Splunk SOAR distributed by Splunk. Versions prior to 1.5.2 are vulnerable; the fix requires Splunk SOAR 8.6.0 or newer to support the updated app.
Risk and Exploitability
The flaw receives a CVSS score of 4.3 indicating moderate severity. No exploitable code or remote attack vector is disclosed, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user who has permission to run actions within the Splunk SOAR platform, making the threat primarily internal; users with such privileges could retrieve the temporary password from the UI. The risk is mitigated by proper privilege management and by preventing untrusted users from executing action commands.
OpenCVE Enrichment