Impact
In versions prior to 1.0.43, the Splunk On-Call (VictorOps) app stores an API key in a KV Store without fully masking it, allowing users without admin or power privileges to read a partially masked key. This leads to unauthorized disclosure of sensitive credentials used by the application, exposing potential service access. The weakness is a CWE‑312 type information‑leak flaw.
Affected Systems
The vulnerability affects the Splunk On-Call (VictorOps) application for Splunk, specifically all releases on Splunkbase with a version lower than 1.0.43. No other Splunk components are listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. The EPSS score is not available but the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a widely exploited risk at this time. The attack likely requires an internal user role that has read access to the app’s KV Store, i.e., a non‑admin Splunk user who can view the application data. As such, exploitation is possible in environments where such users exist and are granted read permissions to the KV Store. The absence of remote code execution or privilege escalation limits the severity, but the disclosed API key can still be leveraged to authenticate to downstream services controlled by that key.
OpenCVE Enrichment