Impact
The Zoom app for Splunk SOAR in versions earlier than 3.2.2 leaves action parameters for passwords and personal meeting IDs in cleartext. A user with a role that allows running actions can invoke actions such as create meeting, update meeting, or update user settings and see the credentials displayed in the interface, exposing sensitive meeting and personal meeting ID passwords to the attacker. This constitutes an information‑disclosure vulnerability that compromises confidentiality of Zoom meeting data.
Affected Systems
Splunk SOAR installations that use the Zoom app for Splunk SOAR version 3.2.1 or earlier run on Splunk SOAR 8.6.0 or higher. Any user with a role that grants permission to execute these actions on those versions is affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. No EPSS score is available and the issue is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation. The vulnerability can be abused by any user who has legitimate action‑execution rights; the attack vector is therefore internal, relying on authorized access rather than remote code execution. Exploitation results in the disclosure of meeting passwords, potentially enabling unauthorized participation in Zoom meetings.
OpenCVE Enrichment