Impact
The connector failed to mask the archive_password parameter when running detonate file or detonate url actions. Users with permission to execute actions can view the clear‑text password in the UI, exposing the credential that protects the encrypted archive. This disclosure could allow an attacker to decrypt the archive or reuse the password for other systems, directly compromising data confidentiality.
Affected Systems
Splunk Attack Analyzer Connector for Splunk SOAR versions earlier than 2.2.1 on Splunk SOAR 8.6.0 or higher. The issue exists only in versions below 2.2.1; upgrading to the fixed release or removing the app mitigates the problem.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. EPSS information is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. Exploitation requires a user with action‑execution rights, so the attack vector is internal. An attacker could read the password from the UI, then use it to decrypt or otherwise compromise the archive.
OpenCVE Enrichment