Cleartext transmission of sensitive information in Splunk Add-on Builder and Splunk CloudConnect SDK - CVE-2023-22943
Published: February 20, 2023
Splunk Add-on Builder
Splunk CloudConnect SDK
Splunk Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software can send requests to third-party APIs through the REST API Modular Input using unencrypted HTTP protocol instead of HTTPS. A remote attacker with ability to intercept network traffic can gain access to sensitive data.