Impact
The Venafi app for Splunk SOAR released before version 2.1.4 contains an information disclosure flaw. The app’s get‑certificate action exposes keystore and private‑key passwords in cleartext because the action parameters are not masked. As a result, a user with a role that permits running actions could capture sensitive credentials directly from the Splunk SOAR user interface. The weakness corresponds to CWE‑312, representing cleartext storage of sensitive information. The impact is a confidentiality breach that could allow attackers to access secured resources or compromise further system components.
Affected Systems
The vulnerability affects the Venafi app for Splunk SOAR from Splunk. All releases prior to 2.1.4 are vulnerable. In addition, the fixed app requires Splunk SOAR 8.6.0 or higher, so any environment using an earlier SOAR version cannot immediately deploy the patched connector.
Risk and Exploitability
The CVSS score for the issue is 4.3, indicating low overall severity, and the EPSS score is not available, suggesting no publicly known exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a user with credentials that grant the ability to run actions within Splunk SOAR; the attacker must access the web console and invoke the get‑certificate action. Because the exposure is triggered by a legitimate UI function, the attack vector is internal and dependent on privileged user access. While the risk is moderate due to the confidence of data leakage, stakeholders should consider the business impact if sensitive credentials are compromised.
OpenCVE Enrichment