In versions 1.0.67 and lower of the Splunk App for SOAR,...
Moderate severity
Unreviewed
Published
Jan 7, 2025
to the GitHub Advisory Database
•
Updated Jan 7, 2025
Description
Published by the National Vulnerability Database
Jan 7, 2025
Published to the GitHub Advisory Database
Jan 7, 2025
Last updated
Jan 7, 2025
In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the
admin_all_objects
capability to thesplunk_app_soar
role. This addition could lead to improper access control for a low-privileged user that does not hold the “admin“ Splunk roles.References