Impact
The vulnerability is an information disclosure flaw in the Phantom app for Splunk SOAR, where a user with permission to run actions can view a sensitive archive password in cleartext. The flaw occurs because the app fails to mask the password field in the deflate item action, exposing it in the UI. This leads to unauthorized exposure of credential material, compromising confidentiality for anyone with access to the interface.
Affected Systems
The affected product is the Phantom app for Splunk SOAR from Splunk, versions below 3.8.5. The fix requires Splunk SOAR 8.6.0 or higher; therefore, systems running older versions of both the app and the platform are vulnerable. The vulnerability impacts any role that can execute actions, including users with elevated permissions such as administrators or managers.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available, so the current exploit probability is unclear. The vulnerability is not listed in the CISA KEV catalog, which suggests no known widespread exploitation. Attackers would need to be authenticated and have action‑execution rights, meaning only privileged account holders can exploit the weakness. Consequently, the risk is confined to users who can run actions rather than arbitrary external attackers.
OpenCVE Enrichment